Where
-Infinity
0

Sangoma Certified Asteriskast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation

Risk 56
Severity
8.8
EPSS
0.02%
First published (updated )

Sangoma Certified AsteriskAsterisk vulnerable to potential privilege escalation

Risk 51
Severity
7.8
EPSS
0.02%
First published (updated )

Sangoma Certified AsteriskAsterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection

Risk 27
Severity
6.5
EPSS
0.10%
First published (updated )

Sangoma Certified AsteriskThe Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization

Risk 27
Severity
6.1
EPSS
0.03%
First published (updated )

Sangoma Certified AsteriskAsterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma AsteriskAsterisk can crash from a specifically malformed Authorization header in an incoming SIP request

Risk 43
Severity
7.5
First published (updated )

Sangoma Certified AsteriskAsterisk remotely exploitable leak of RTP UDP ports and internal resources

Risk 38
Severity
6.5
First published (updated )

Sangoma Certified AsteriskAsterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation

Risk 38
Severity
6.5
First published (updated )

Sangoma Certified Asteriskcli_permissions.conf: deny option does not work for disallowing shell commands

Risk 51
Severity
7.8
EPSS
0.07%
First published (updated )

Sangoma Certified AsteriskUsing malformed From header can forge identity with ";" or NULL in name portion

Risk 31
Severity
7.7
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Asterisk AsteriskInsecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary cod…

Risk 86
Severity
9.8
First published (updated )

Sangoma Certified AsteriskA malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used

Risk 33
Severity
5.7
First published (updated )

Asterisk Certified AsteriskAsterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan

Risk 79
Severity
8.8
First published (updated )

asterisk security leases 18.23.1, 20.8.1, & 21.3.1

Asterisk AsteriskAsterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests

Risk 21
Severity
5.8
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

[ES2023-01] Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation

Asterisk Certified AsteriskNull Pointer Dereference

Risk 38
Severity
6.5
First published (updated )

Asterisk Certified AsteriskUse after free in PJSIP

Risk 89
Severity
9.8
First published (updated )

Asterisk Certified AsteriskOut-of-bounds read in multipart parsing in PJSIP

Risk 69
Severity
9.1
First published (updated )

Asterisk Certified AsteriskPotential integer underflow upon receiving STUN message in PJSIP

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Digium Certified AsteriskA res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16…

Risk 32
Severity
5.3
First published (updated )

Sangoma AsteriskAn issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x befor…

Risk 38
Severity
6.5
First published (updated )

Debian Debian Linuxasterisk allows calls on prohibited networks

Risk 43
Severity
7.5
First published (updated )

Sangoma AsteriskAn issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via T…

Risk 38
Severity
6.8
First published (updated )

Sangoma AsteriskA memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Asterisk Open SourceBuffer Overflow

Risk 52
Severity
7.5
First published (updated )

Asterisk Open SourceBuffer Overflow

Risk 26
Severity
5
First published (updated )

Asterisk Open SourceInfoleak

Risk 26
Severity
5
First published (updated )

Asterisk Open SourceIncomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 a…

Risk 78
Severity
9
First published (updated )

Asterisk Open SourceNull Pointer Dereference

Risk 21
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203