Search CVE reports


Toggle filters

1 – 10 of 194 results


CVE-2026-42225

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-41416

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-41415

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-40892

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-40614

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-23741

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on...

1 affected package

asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23740

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that...

1 affected package

asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23739

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe...

1 affected package

asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23738

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are...

1 affected package

asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-1131

Medium priority
Needs evaluation

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh...

1 affected package

asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages