Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 219

Количество 219

ubuntu логотип

CVE-2024-4877

больше 1 года назад

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-4877

больше 1 года назад

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-4877

больше 1 года назад

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, le ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-28882

около 2 лет назад

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-28882

около 2 лет назад

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-28882

около 2 лет назад

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple ex ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-27903

около 2 лет назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-27903

около 2 лет назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-27903

около 2 лет назад

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-27459

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-27459

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-27459

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-24974

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-24974

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-24974

около 2 лет назад

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0547

больше 4 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-0547

больше 4 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-0547

больше 4 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2021-3606

около 5 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-3606

около 5 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-4877

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

CVSS3: 8.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-4877

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

CVSS3: 8.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-4877

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, le ...

CVSS3: 8.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-28882

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

CVSS3: 4.3
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-28882

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

CVSS3: 4.3
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-28882

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple ex ...

CVSS3: 4.3
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
9%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS3: 9.8
9%
Низкий
около 2 лет назад
debian логотип
CVE-2024-27903

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...

CVSS3: 9.8
9%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
8%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

CVSS3: 7.8
8%
Низкий
около 2 лет назад
debian логотип
CVE-2024-27459

The interactive service in OpenVPN 2.6.9 and earlier allows an attacke ...

CVSS3: 7.8
8%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
10%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

CVSS3: 7.5
10%
Низкий
около 2 лет назад
debian логотип
CVE-2024-24974

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVP ...

CVSS3: 7.5
10%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

CVSS3: 7.8
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arb ...

CVSS3: 7.8
0%
Низкий
около 5 лет назад

Уязвимостей на страницу