Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 219

Количество 219

debian логотип

CVE-2017-7478

около 9 лет назад

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Deni ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2017-12166

почти 9 лет назад

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-12166

почти 9 лет назад

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-12166

почти 9 лет назад

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-6329

больше 9 лет назад

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2016-6329

больше 9 лет назад

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2016-6329

больше 9 лет назад

OpenVPN, when using a 64-bit block cipher, makes it easier for remote ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3459

почти 18 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2008-3459

почти 18 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
EPSS: Низкий
debian логотип

CVE-2008-3459

почти 18 лет назад

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2534

почти 21 год назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2534

почти 21 год назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-2534

почти 21 год назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2533

почти 21 год назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2533

почти 21 год назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2005-2533

почти 21 год назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2532

почти 21 год назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2532

почти 21 год назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2532

почти 21 год назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2531

почти 21 год назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2017-7478

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Deni ...

CVSS3: 7.5
14%
Средний
около 9 лет назад
ubuntu логотип
CVE-2017-12166

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-12166

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-12166

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to ...

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-6329

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
6%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6329

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS3: 5.9
6%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6329

OpenVPN, when using a 64-bit block cipher, makes it easier for remote ...

CVSS3: 5.9
6%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

CVSS2: 7.6
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when ...

CVSS2: 7.6
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not ena ...

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode ...

CVSS2: 2.1
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
3%
Низкий
почти 21 год назад
debian логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue w ...

CVSS2: 5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
2%
Низкий
почти 21 год назад

Уязвимостей на страницу