Логотип exploitDog
product: "openvpn"
Консоль
Логотип exploitDog

exploitDog

product: "openvpn"

Количество 186

Количество 186

github логотип

GHSA-p2qj-cw7j-f6wr

около 3 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

EPSS: Низкий
github логотип

GHSA-mww5-q78w-ffpv

около 3 лет назад

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

EPSS: Низкий
github логотип

GHSA-jg57-vh55-3g23

больше 1 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-j3mr-328w-64j3

около 3 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

EPSS: Низкий
github логотип

GHSA-8fqr-f734-rf7m

около 3 лет назад

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

EPSS: Низкий
github логотип

GHSA-5cc7-3r85-874q

около 3 лет назад

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

EPSS: Низкий
github логотип

GHSA-26pq-368c-c8f2

около 3 лет назад

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

EPSS: Низкий
ubuntu логотип

CVE-2023-46850

больше 1 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-46850

больше 1 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-46850

больше 1 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-46849

больше 1 года назад

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46849

больше 1 года назад

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-46849

больше 1 года назад

Using the --fragment option in certain configuration setups OpenVPN ve ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8104

больше 10 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-8104

больше 10 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8104

больше 10 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5455

почти 11 лет назад

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2013-2061

больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-2061

больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-2061

больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, ...

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p2qj-cw7j-f6wr

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

1%
Низкий
около 3 лет назад
github логотип
GHSA-mww5-q78w-ffpv

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

1%
Низкий
около 3 лет назад
github логотип
GHSA-jg57-vh55-3g23

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-j3mr-328w-64j3

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

1%
Низкий
около 3 лет назад
github логотип
GHSA-8fqr-f734-rf7m

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

5%
Низкий
около 3 лет назад
github логотип
GHSA-5cc7-3r85-874q

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

3%
Низкий
около 3 лет назад
github логотип
GHSA-26pq-368c-c8f2

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined ...

CVSS3: 9.8
2%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN ve ...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-5455

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS2: 6.9
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, ...

CVSS2: 2.6
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу