Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"
OpenVPN

OpenVPNсвободная реализация технологии виртуальной частной сети (VPN) с открытым исходным кодом для создания зашифрованных каналoв типа точка-точка или сервер-клиенты между компьютерами.

Релизный цикл, информация об уязвимостях

Продукт: OpenVPN
Вендор: openvpn

График релизов

2.12.22.32.42.52.6200920102011201220132014201520162017201820192020202120222023202420252026

Недавние уязвимости OpenVPN

Количество 188

debian логотип

CVE-2013-2061

больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-2061

больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3459

почти 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
debian логотип

CVE-2008-3459

почти 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2008-3459

почти 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2006-2229

около 19 лет назад

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2006-2229

около 19 лет назад

OpenVPN 2.0.7 and earlier, when configured to use the --management opt ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2006-1629

больше 19 лет назад

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

CVSS2: 9
EPSS: Низкий
debian логотип

CVE-2006-1629

больше 19 лет назад

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute a ...

CVSS2: 9
EPSS: Низкий
ubuntu логотип

CVE-2006-1629

больше 19 лет назад

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

CVSS2: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, ...

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2006-2229

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

CVSS2: 4
1%
Низкий
около 19 лет назад
debian логотип
CVE-2006-2229

OpenVPN 2.0.7 and earlier, when configured to use the --management opt ...

CVSS2: 4
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2006-1629

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

CVSS2: 9
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-1629

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute a ...

CVSS2: 9
4%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1629

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

CVSS2: 9
4%
Низкий
больше 19 лет назад

Уязвимостей на страницу


Поделиться