Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 254

Количество 254

github логотип

GHSA-q6wh-cc86-fx6h

больше 4 лет назад

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

EPSS: Низкий
github логотип

GHSA-p99v-qjfm-8vvq

почти 3 года назад

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p2qj-cw7j-f6wr

больше 4 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

EPSS: Низкий
github логотип

GHSA-mww5-q78w-ffpv

больше 4 лет назад

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jg57-vh55-3g23

почти 3 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-j3mr-328w-64j3

больше 4 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

EPSS: Низкий
github логотип

GHSA-8fqr-f734-rf7m

больше 4 лет назад

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

EPSS: Низкий
github логотип

GHSA-5cc7-3r85-874q

больше 4 лет назад

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

EPSS: Низкий
github логотип

GHSA-26pq-368c-c8f2

больше 4 лет назад

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

EPSS: Низкий
ubuntu логотип

CVE-2023-46850

почти 3 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-46850

почти 3 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-46850

почти 3 года назад

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-46849

почти 3 года назад

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46849

почти 3 года назад

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-46849

почти 3 года назад

Using the --fragment option in certain configuration setups OpenVPN ve ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8104

почти 12 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-8104

почти 12 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8104

почти 12 лет назад

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5455

около 12 лет назад

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2061

почти 13 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q6wh-cc86-fx6h

OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-p99v-qjfm-8vvq

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-p2qj-cw7j-f6wr

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-mww5-q78w-ffpv

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-jg57-vh55-3g23

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-j3mr-328w-64j3

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-8fqr-f734-rf7m

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-5cc7-3r85-874q

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-26pq-368c-c8f2

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

3%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
debian логотип
CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined ...

CVSS3: 9.8
2%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN ve ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
3%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

CVSS2: 6.8
3%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before ...

CVSS2: 6.8
3%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-5455

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVSS3: 5.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-2061

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVSS2: 2.6
3%
Низкий
почти 13 лет назад

Уязвимостей на страницу