Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.7% | — | Asterisk Business EditionAsterisk Open SourceAsterisk S800i Appliance | 14/1/2009 | 16/6/2026 | IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account… | |
| Modificada | Alta (7.2) | 0.47% | — | Asterisk Zaptel | 26/12/2008 | 16/6/2026 | Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396 that uses the wrong variable in a range check against the value… | |
| Modificada | Media (4.3) | 2.0% | — | Asterisk Business EditionAsterisk Open Source | 17/12/2008 | 16/6/2026 | Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname matching. | |
| Modificada | Alta (7.2) | 0.35% | — | Asterisk Zaptel | 9/12/2008 | 16/6/2026 | Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZT_SPANCONFIG ioctl. | |
| Modificada | Baja (3.5) | 1.9% | — | Asterisk P B XTrixbox PBX | 4/9/2008 | 16/6/2026 | Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled,… | |
| Modificada | Alta (7.8) | 3.4% | — | Asterisk Appliance Developer KITAsterisk Business EditionAsterisknowAsterisk Open Source | 24/7/2008 | 16/6/2026 | The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.8) | 28% | 💥 Exploit | Asterisk | 22/7/2008 | 16/6/2026 | The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service… | |
| Modificada | Media (5) | 3.6% | — | Asterisk-addons | 5/6/2008 | 16/6/2026 | The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is intended solely for localhost communication, and interprets some TCP application-data fields as addresses of memory to free, which allows remote attackers to cause a… | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Asterisk Business EditionAsterisk Open Source | 4/6/2008 | 16/6/2026 | Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the… | |
| Modificada | Alta (7.1) | 1.4% | — | Asterisk Appliance Developer KITAsterisk Business EditionAsterisknowAsterisk Open Source+1 | 23/4/2008 | 16/6/2026 | The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a… | |
| Modificada | Media (4.3) | 2.7% | — | Asterisk Appliance Developer KITAsterisk Business EditionAsterisknowAsterisk Open Source+1 | 23/4/2008 | 16/6/2026 | The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls,… | |
| Modificada | Alta (9.3) | 3.8% | — | AsteriskAsterisk Appliance Developer KITAsterisk Business EditionAsterisknow+1 | 24/3/2008 | 16/6/2026 | The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it… | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Asterisk Appliance Developer KITAsterisk Business EditionAsterisknowAsterisk Open Source+1 | 24/3/2008 | 16/6/2026 | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a… | |
| Modificada | Media (5.8) | 3.2% | — | Asterisk Open Source | 20/3/2008 | 16/6/2026 | Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function. | |
| Modificada | Alta (8.8) | 2.3% | — | AsteriskAsterisk Appliance Developer KITAsterisk Business EditionAsterisknow+2 | 20/3/2008 | 16/6/2026 | Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 revision 109393; and s800i 1.0.x before 1.1.0.2; allows remote… | |
| Modificada | Media (5) | 25% | 💥 Exploit | Asterisk Appliance Developer KITAsterisk Business EditionAsterisknowAsterisk Open Source+1 | 8/1/2008 | 16/6/2026 | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message… | |
| Modificada | Media (4.3) | 2.0% | — | Asterisk Business EditionAsterisk Open Source | 20/12/2007 | 16/6/2026 | Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows… | |
| Modificada | Media (6.5) | 2.8% | — | Digium AsteriskDebian Linux | 30/11/2007 | 16/6/2026 | SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments. | |
| Modificada | Alta (7.5) | 2.7% | — | Digium Asterisk | 30/11/2007 | 16/6/2026 | SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (4.6) | 0.36% | — | Asterisk Zaptel | 29/10/2007 | 16/6/2026 | Buffer overflow in sethdlc.c in the Asterisk Zaptel 1.4.5.1 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that the application requires root access, so privilege boundaries are not crossed | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Asterisk-addons | 17/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record. | |
| Modificada | Media (6.8) | 3.9% | — | Digium Asterisk | 12/10/2007 | 16/6/2026 | Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of… | |
| Modificada | Media (5) | 3.0% | — | Asterisk | 28/8/2007 | 16/6/2026 | Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail. | |
| Modificada | Media (5) | 1.8% | — | AsteriskAsterisk Appliance Developer KITAsterisknow | 22/8/2007 | 16/6/2026 | The SIP channel driver (chan_sip) in Asterisk Open Source 1.4.x before 1.4.11, AsteriskNOW before beta7, Asterisk Appliance Developer Kit 0.x before 0.8.0, and s800i (Asterisk Appliance) 1.x before 1.0.3 allows remote attackers to cause a denial of service (memory exhaustion) via a SIP dialog that causes a large… | |
| Modificada | Baja (3.5) | 1.1% | — | AsteriskAsterisk Appliance Developer KITAsterisknowAsterisk S800i | 9/8/2007 | 16/6/2026 | The Skinny channel driver (chan_skinny) in Asterisk Open Source before 1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and Appliance s800i before 1.0.3 allows remote authenticated users to cause a denial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet with a capabilities… |