VYPR
Vendor

Asterisk

The asterisk, *, is a typographical symbol that is a stylised image of a star. An asterisk is usually five- or six-pointed in print and six- or eight-pointed when handwritten, though more complex forms exist. Its most common use is to call out a footnote. It is also often used to censor words considered offensive. It is often vocalized as star, especially by computer scientists and mathematicians.

Products
22
CVEs
163
Across products
312
Status
Private

Products

22

Recent CVEs

163
View all 163 CVEs →
  • CVE-2017-14100CriSep 2, 2017
    risk 0.65cvss 9.8epss 0.15

    In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is…

  • CVE-2024-57520CriFeb 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka…

  • CVE-2022-26651CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly…

  • CVE-2022-26499CriApr 15, 2022
    risk 0.60cvss 9.1epss 0.08

    An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

  • CVE-2017-17090HigDec 2, 2017
    risk 0.58cvss 7.5epss 0.82

    An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the…

  • CVE-2017-16671HigNov 9, 2017
    risk 0.57cvss 8.8epss 0.03

    A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone…

  • CVE-2018-7284HigFeb 22, 2018
    risk 0.56cvss 7.5epss 0.58

    A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept…

  • CVE-2017-17850HigDec 27, 2017
    risk 0.55cvss 7.5epss 0.75

    An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and…

  • CVE-2018-17281HigSep 24, 2018
    risk 0.53cvss 7.5epss 0.53

    There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to…

  • CVE-2017-14098HigSep 2, 2017
    risk 0.53cvss 7.5epss 0.50

    In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.

  • CVE-2025-1131HigSep 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root,…

  • CVE-2025-47780HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI)…

  • CVE-2025-47779HigMay 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An…

  • CVE-2022-26498HigApr 15, 2022
    risk 0.50cvss 7.5epss 0.16

    An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and…

  • CVE-2021-32558HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.09

    An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

  • CVE-2021-26717HigFeb 18, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in…

  • CVE-2019-18976HigNov 22, 2019
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different…

  • CVE-2009-3723HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    asterisk allows calls on prohibited networks

  • CVE-2016-7550HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.02

    asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

  • CVE-2018-7285HigFeb 22, 2018
    risk 0.49cvss 7.5epss 0.05

    A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a codec using a different payload number, these desired ones…