İçeriğe atla
Noroxi

OpenVPN kayıtları

openvpn üreticisine ait 79 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%55,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

79 kayıt
  • CVE-2024-1305
    44Planlayın

    tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use

    KritikCVSS 9,8İstismar yokEPSS %15

    openvpn · tap-windows68 Tem 2024

  • CVE-2024-27903
    42Planlayın

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary

    KritikCVSS 9,8İstismar yokEPSS %9

    openvpn · openvpn8 Tem 2024

  • CVE-2017-12166
    40Planlayın

    OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly r

    KritikCVSS 9,8İstismar yokEPSS %4

    openvpn · openvpn3 Eki 2017

  • CVE-2022-0547
    40Planlayın

    OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u

    KritikCVSS 9,8İstismar yokEPSS %4

    openvpn · openvpn18 Mar 2022

  • CVE-2023-46850
    40Planlayın

    Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending net

    KritikCVSS 9,8İstismar yokEPSS %2

    openvpn · openvpn10 Kas 2023

  • CVE-2020-8953
    39İzleyin

    OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

    KritikCVSS 9,8İstismar yokEPSS %1

    openvpn · openvpn access server13 Şub 2020

  • CVE-2006-1629
    37İzleyin

    OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviro

    KritikCVSS 9,0İstismar yokEPSS %3

    openvpn · openvpn6 Nis 2006

  • CVE-2018-7544
    37İzleyin

    A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.

    KritikCVSS 9,1İstismar yokEPSS %2

    openvpn · openvpn16 Mar 2018

  • CVE-2026-9560
    37İzleyin

    Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands w

    KritikCVSS 9,4Kavram kanıtıEPSS %0

    openvpn · connect26 May 2026

  • CVE-2024-5594
    36İzleyin

    OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected ar

    KritikCVSS 9,1İstismar yokEPSS %1

    openvpn · openvpn6 Oca 2025

  • CVE-2025-12106
    36İzleyin

    Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP

    KritikCVSS 9,1İstismar yokEPSS %1

    openvpn · openvpn1 Ara 2025

  • CVE-2024-4877
    35İzleyin

    OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI c

    YüksekCVSS 8,8İstismar yokEPSS %0

    openvpn · openvpn3 Nis 2025

  • CVE-2017-7478
    34İzleyin

    OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.

    YüksekCVSS 7,5Kavram kanıtıEPSS %14

    openvpn · openvpn15 May 2017

  • CVE-2024-24974
    33İzleyin

    The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker

    YüksekCVSS 7,5İstismar yokEPSS %10

    openvpn · openvpn8 Tem 2024

  • CVE-2024-27459
    33İzleyin

    The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute a

    YüksekCVSS 7,8İstismar yokEPSS %8

    openvpn · openvpn8 Tem 2024

  • CVE-2023-7235
    33İzleyin

    The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN b

    YüksekCVSS 8,4İstismar yokEPSS %0

    openvpn · openvpn gui21 Şub 2024

  • CVE-2020-15078
    31İzleyin

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured

    YüksekCVSS 7,5İstismar yokEPSS %5

    openvpn · openvpn26 Nis 2021

  • CVE-2017-7508
    31İzleyin

    OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.

    YüksekCVSS 7,5İstismar yokEPSS %5

    openvpn · openvpn27 Haz 2017

  • CVE-2005-3393
    31İzleyin

    Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code vi

    YüksekCVSS 7,5İstismar yokEPSS %3

    openvpn · openvpn1 Kas 2005

  • CVE-2008-3459
    31İzleyin

    Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbit

    YüksekCVSS 7,6İstismar yokEPSS %2

    openvpn · openvpn4 Ağu 2008

  • CVE-2020-36382
    31İzleyin

    OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authent

    YüksekCVSS 7,5İstismar yokEPSS %2

    openvpn · openvpn access server4 Haz 2021

  • CVE-2021-3613
    31İzleyin

    OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if pre

    YüksekCVSS 7,8İstismar yokEPSS %1

    openvpn · connect2 Tem 2021

  • CVE-2020-9442
    31İzleyin

    OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    openvpn · connect28 Şub 2020

  • CVE-2018-9336
    31İzleyin

    openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory

    YüksekCVSS 7,8İstismar yokEPSS %1

    openvpn · openvpn1 May 2018

  • CVE-2020-15076
    31İzleyin

    Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks

    YüksekCVSS 7,8İstismar yokEPSS %0

    openvpn · private tunnel26 May 2021