Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 254

Количество 254

nvd логотип

CVE-2026-13122

2 месяца назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-13122

2 месяца назад

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-13117

около 2 месяцев назад

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-13117

около 2 месяцев назад

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-13117

около 2 месяцев назад

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-13117

около 2 месяцев назад

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 thr ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-12996

около 2 месяцев назад

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-12996

около 2 месяцев назад

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-12996

около 2 месяцев назад

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-12996

около 2 месяцев назад

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-12932

около 2 месяцев назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-12932

около 2 месяцев назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-12932

около 2 месяцев назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-12932

около 2 месяцев назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-11771

около 2 месяцев назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-11771

около 2 месяцев назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-11771

около 2 месяцев назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-11771

около 2 месяцев назад

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-11604

3 месяца назад

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-2704

больше 1 года назад

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

CVSS3: 5.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 5.3
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 thr ...

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-11604

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-2704

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу