Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

OpenVPN

OpenVPNсвободная реализация технологии виртуальной частной сети (VPN) с открытым исходным кодом для создания зашифрованных каналoв типа точка-точка или сервер-клиенты между компьютерами.

Релизный цикл, информация об уязвимостях

Продукт: OpenVPN
Вендор: openvpn

График релизов

2.62.72023202420252026202720282029

Недавние уязвимости OpenVPN

Количество 254

ubuntu логотип

CVE-2005-3393

почти 21 год назад

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3393

почти 21 год назад

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-2531

около 21 года назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authe ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2532

около 21 года назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2533

около 21 года назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2005-2534

около 21 года назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2532

около 21 года назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2533

около 21 года назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2531

около 21 года назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2534

около 21 года назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2005-3393

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3393

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
debian логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authe ...

CVSS2: 5
2%
Низкий
около 21 года назад
debian логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
3%
Низкий
около 21 года назад
debian логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
1%
Низкий
около 21 года назад
debian логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
1%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
3%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
1%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
2%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
около 21 года назад

Уязвимостей на страницу


Поделиться