Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 254

Количество 254

github логотип

GHSA-3c2r-pvhv-53p8

больше 4 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

EPSS: Низкий
github логотип

GHSA-2w3j-7x55-5cx2

больше 4 лет назад

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2cgw-c87g-ww8q

больше 4 лет назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-22j3-3q48-2rmj

3 месяца назад

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-40215

3 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-40215

3 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-40215

3 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-40215

3 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2026-35058

3 месяца назад

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-35058

3 месяца назад

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-35058

3 месяца назад

Improper validation of packet length during tls-crypt-v2 key extractio ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-13698

2 месяца назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-13698

2 месяца назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-13698

2 месяца назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-13698

2 месяца назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-13379

около 2 месяцев назад

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-13379

около 2 месяцев назад

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-13379

около 2 месяцев назад

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 al ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-13122

2 месяца назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-13122

2 месяца назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c2r-pvhv-53p8

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2w3j-7x55-5cx2

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2cgw-c87g-ww8q

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22j3-3q48-2rmj

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-40215

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-40215

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-40215

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-40215

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ...

CVSS3: 7.4
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extractio ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-13698

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-13698

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 4.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-13698

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-13698

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2 ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 al ...

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу