CVE Tools

Digium-inc

5 CVEs tracked since 2016. Since Feb 2016, none of them reached CISA KEV.

Digium-inc CVEs per month

Feb 2016 to Jul 2021. Point at a month, or focus the strip and use the arrow keys.
Digium-inc CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0220
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-0730

Products

The products that kept showing up in Digium-inc's monthly top three, with their CVEs summed over those months.

  1. Asterisk52 months
  2. Certified Asterisk21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Digium-inc.

  1. CVE-2025-1131Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation7.8
  2. CVE-2025-54995Asterisk remotely exploitable leak of RTP UDP ports and internal resources6.5
  3. CVE-2025-47779Using malformed From header can forge identity with ";" or NULL in name portion7.7
  4. CVE-2024-42491A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used5.7
  5. CVE-2024-42365Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan7.4
  6. CVE-2023-49786Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation7.5
  7. CVE-2023-37457Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'7.5
  8. CVE-2023-49294Asterisk Path Traversal vulnerability4.9
  9. CVE-2021-32558An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driv...7.5
  10. CVE-2021-31878An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.6.5
  11. CVE-2021-32686Denial of Service in PJSIP5.9
  12. CVE-2019-18976An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c li...7.5
  13. CVE-2017-14100In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. ...9.8
  14. CVE-2016-2316chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.co...5.9
  15. CVE-2016-2232Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to ...6.5

The record

Peak rank
#61 in Feb 2016
Busiest month shown
Jul 2021, 3 CVEs
Months with a KEV entry
0 since Feb 2016
Monthly snapshots
2 since 2016
Digium-inc's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store