Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"

Количество 188

Количество 188

nvd логотип

CVE-2016-6329

больше 8 лет назад

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2016-6329

больше 8 лет назад

OpenVPN, when using a 64-bit block cipher, makes it easier for remote ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3459

около 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2008-3459

около 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
debian логотип

CVE-2008-3459

около 17 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2534

почти 20 лет назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2534

почти 20 лет назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-2534

почти 20 лет назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2533

почти 20 лет назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2533

почти 20 лет назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2005-2533

почти 20 лет назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2532

почти 20 лет назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2532

почти 20 лет назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2532

почти 20 лет назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2531

почти 20 лет назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2531

почти 20 лет назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2531

почти 20 лет назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authe ...

CVSS2: 5
EPSS: Низкий
fstec логотип

BDU:2025-07445

около 2 месяцев назад

Уязвимость драйвера ovpn-dco-win программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2025-03850

около 1 года назад

Уязвимость службы Interactive Service (iservice) клиента OpenVPN GUI программного обеспечения OpenVPN, позволяющая нарушителю получить несанкционированный доступ к учетной записи пользователя

CVSS3: 5.7
EPSS: Низкий
fstec логотип

BDU:2021-03572

около 4 лет назад

Уязвимость библиотеки OpenSSL программного обеспечения OpenVPN, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-6329

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
8%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-6329

OpenVPN, when using a 64-bit block cipher, makes it easier for remote ...

CVSS3: 5.9
8%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
1%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
0%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
0%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
0%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authe ...

CVSS2: 5
1%
Низкий
почти 20 лет назад
fstec логотип
BDU:2025-07445

Уязвимость драйвера ovpn-dco-win программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2025-03850

Уязвимость службы Interactive Service (iservice) клиента OpenVPN GUI программного обеспечения OpenVPN, позволяющая нарушителю получить несанкционированный доступ к учетной записи пользователя

CVSS3: 5.7
0%
Низкий
около 1 года назад
fstec логотип
BDU:2021-03572

Уязвимость библиотеки OpenSSL программного обеспечения OpenVPN, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу