← Vulnerability feed

Vulnerability record · CVE-2007-3762 · published 18 July 2007

CVE-2007-3762: Asterisk vulnerability

Asterisk · Asterisk

Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.

9.3 CVSS 2.0 High EPSS 5.5% · top 7.5%
9.3CVSS 2.0 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3762 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2488Asterisk vulnerabilityThe IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss …EPSS 4.3%9.3CVE-2008-1390Asterisk vulnerabilityThe AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, Asteri…EPSS 3.8%8.8CVE-2024-42365Asterisk vulnerabilityAsterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-…EPSS 4.7%8.8CVE-2008-1332Asterisk permissions and access controls vulnerabilityUnspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…EPSS 2.3%7.8CVE-2009-2346Asterisk memory buffer overflow vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.…EPSS 2.6%7.8CVE-2008-3264Asterisk appliance developer kit improper authentication vulnerabilityThe FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B…EPSS 3.4%7.8CVE-2008-3263Asterisk vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …EPSS 28%7.8CVE-2007-2294Asterisk vulnerabilityThe Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 auth…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2007-3762), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.