Перейти к содержимому
Noroxi

Записи OpenVPN

79 опубликованных записей вендора openvpn.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
55,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

79 записей
  • CVE-2024-1305
    44В плане

    tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use

    КритическаяCVSS 9,8Эксплойта нетEPSS 15 %

    openvpn · tap-windows68 июл. 2024 г.

  • CVE-2024-27903
    42В плане

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    openvpn · openvpn8 июл. 2024 г.

  • CVE-2017-12166
    40В плане

    OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly r

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    openvpn · openvpn3 окт. 2017 г.

  • CVE-2022-0547
    40В плане

    OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    openvpn · openvpn18 мар. 2022 г.

  • CVE-2023-46850
    40В плане

    Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending net

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    openvpn · openvpn10 нояб. 2023 г.

  • CVE-2020-8953
    39Наблюдать

    OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openvpn · openvpn access server13 февр. 2020 г.

  • CVE-2006-1629
    37Наблюдать

    OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD enviro

    КритическаяCVSS 9,0Эксплойта нетEPSS 3 %

    openvpn · openvpn6 апр. 2006 г.

  • CVE-2018-7544
    37Наблюдать

    A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    openvpn · openvpn16 мар. 2018 г.

  • CVE-2026-9560
    37Наблюдать

    Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands w

    КритическаяCVSS 9,4Proof of conceptEPSS 0 %

    openvpn · connect26 мая 2026 г.

  • CVE-2024-5594
    36Наблюдать

    OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected ar

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    openvpn · openvpn6 янв. 2025 г.

  • CVE-2025-12106
    36Наблюдать

    Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    openvpn · openvpn1 дек. 2025 г.

  • CVE-2024-4877
    35Наблюдать

    OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI c

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    openvpn · openvpn3 апр. 2025 г.

  • CVE-2017-7478
    34Наблюдать

    OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.

    ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

    openvpn · openvpn15 мая 2017 г.

  • CVE-2024-24974
    33Наблюдать

    The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker

    ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %

    openvpn · openvpn8 июл. 2024 г.

  • CVE-2024-27459
    33Наблюдать

    The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute a

    ВысокаяCVSS 7,8Эксплойта нетEPSS 8 %

    openvpn · openvpn8 июл. 2024 г.

  • CVE-2023-7235
    33Наблюдать

    The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN b

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    openvpn · openvpn gui21 февр. 2024 г.

  • CVE-2020-15078
    31Наблюдать

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    openvpn · openvpn26 апр. 2021 г.

  • CVE-2017-7508
    31Наблюдать

    OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    openvpn · openvpn27 июн. 2017 г.

  • CVE-2005-3393
    31Наблюдать

    Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code vi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    openvpn · openvpn1 нояб. 2005 г.

  • CVE-2008-3459
    31Наблюдать

    Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbit

    ВысокаяCVSS 7,6Эксплойта нетEPSS 2 %

    openvpn · openvpn4 авг. 2008 г.

  • CVE-2020-36382
    31Наблюдать

    OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authent

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    openvpn · openvpn access server4 июн. 2021 г.

  • CVE-2021-3613
    31Наблюдать

    OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if pre

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    openvpn · connect2 июл. 2021 г.

  • CVE-2020-9442
    31Наблюдать

    OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    openvpn · connect28 февр. 2020 г.

  • CVE-2018-9336
    31Наблюдать

    openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    openvpn · openvpn1 мая 2018 г.

  • CVE-2020-15076
    31Наблюдать

    Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    openvpn · private tunnel26 мая 2021 г.