This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:asterisk:open_source:1.4.19:rc-2 |
| Detail | |||
|---|---|---|---|
| Vendor | Asterisk | First view | 2008-03-19 |
| Product | Open Source | Last view | 2009-09-08 |
| Version | 1.4.19 | Type | Application |
| Edition | |||
| Language | |||
| Update | rc-2 | ||
| CPE Product | cpe:/a:asterisk:open_source | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.8 | 2009-09-08 | CVE-2009-2346 | Network | Low | None Requ... | |
| 7.8 | 2009-08-12 | CVE-2009-2726 | Network | Low | None Requ... | |
| 7.5 | 2008-03-24 | CVE-2008-1289 | Network | Low | None Requ... | |
| 8.8 | 2008-03-19 | CVE-2008-1332 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 50% (2) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| 25% (1) | CWE-399 | Resource Management Errors |
| 25% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
CAPEC : Common Attack Pattern Enumeration & Classificatio
| id | Name |
|---|---|
| CAPEC-2 | Inducing Account Lockout |
| CAPEC-82 | Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi... |
| CAPEC-99 | XML Parser Attack |
| CAPEC-119 | Resource Depletion |
| CAPEC-121 | Locate and Exploit Test APIs |
| id | Name |
|---|---|
| CAPEC-125 | Resource Depletion through Flooding |
| CAPEC-130 | Resource Depletion through Allocation |
| CAPEC-147 | XML Ping of Death |
| CAPEC-197 | XEE (XML Entity Expansion) |
| CAPEC-227 | Denial of Service through Resource Depletion |
| CAPEC-228 | Resource Depletion through DTD Injection in a SOAP Message |
| CAPEC-229 | XML Attribute Blowup |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 57762 | Asterisk IAX2 Call Number Resource Exhaustion Remote DoS |
| 56991 | Asterisk Multiple Function Maximum Width Handling Remote DoS |
| 43416 | Asterisk RTP Payload Handling Multiple Remote Overflows |
| 43415 | Asterisk SIP Channel Driver Unauthenticated Call Remote Privilege Escalation |









