CVE-2018-9336
- EPSS 0.09%
- Veröffentlicht 01.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:21
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory...
CVE-2018-7544
- EPSS 0.38%
- Veröffentlicht 16.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:20
A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitra...
CVE-2017-12166
- EPSS 1.33%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
CVE-2017-7522
- EPSS 1.02%
- Veröffentlicht 27.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
CVE-2017-7521
- EPSS 0.83%
- Veröffentlicht 27.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
CVE-2017-7520
- EPSS 0.87%
- Veröffentlicht 27.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
CVE-2017-7508
- EPSS 0.71%
- Veröffentlicht 27.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet.
CVE-2017-7479
- EPSS 0.71%
- Veröffentlicht 15.05.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
CVE-2017-7478
- EPSS 6.9%
- Veröffentlicht 15.05.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
CVE-2016-6329
- EPSS 4.89%
- Veröffentlicht 31.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka ...