Openvpn

Openvpn

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 30.07.2026 16:42:03
  • Zuletzt bearbeitet 05.08.2026 19:38:24

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

  • EPSS 0.46%
  • Veröffentlicht 30.07.2026 16:38:58
  • Zuletzt bearbeitet 05.08.2026 19:38:07

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

  • EPSS 0.38%
  • Veröffentlicht 30.07.2026 16:36:41
  • Zuletzt bearbeitet 05.08.2026 19:38:34

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

  • EPSS 0.4%
  • Veröffentlicht 30.07.2026 16:32:42
  • Zuletzt bearbeitet 05.08.2026 19:37:47

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

  • EPSS 0.34%
  • Veröffentlicht 30.07.2026 16:28:19
  • Zuletzt bearbeitet 05.08.2026 19:37:28

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

  • EPSS 0.29%
  • Veröffentlicht 06.07.2026 14:32:29
  • Zuletzt bearbeitet 09.07.2026 13:06:19

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

  • EPSS 0.31%
  • Veröffentlicht 06.07.2026 14:13:49
  • Zuletzt bearbeitet 09.07.2026 13:05:30

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

  • EPSS 0.39%
  • Veröffentlicht 08.06.2026 19:59:20
  • Zuletzt bearbeitet 11.08.2026 13:06:12

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 08.06.2026 19:29:56
  • Zuletzt bearbeitet 11.08.2026 13:11:16

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted pac...

  • EPSS 0.32%
  • Veröffentlicht 30.01.2026 18:06:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service