CVE-2025-32787
- EPSS 0.17%
- Veröffentlicht 16.04.2025 21:41:15
- Zuletzt bearbeitet 17.04.2025 20:21:48
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6DefaultRouterInR...
CVE-2025-25565
- EPSS 0.19%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 19.07.2025 02:15:21
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long string on a co...
CVE-2025-25566
- EPSS 0.12%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 19.07.2025 02:15:22
Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because the behavior is limited to a single allocation of a few hundred bytes with ...
CVE-2025-25567
- EPSS 0.17%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 19.07.2025 02:15:22
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,
CVE-2025-25568
- EPSS 0.19%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 19.07.2025 02:15:22
SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has...
CVE-2024-38520
- EPSS 0.06%
- Veröffentlicht 26.06.2024 19:15:13
- Zuletzt bearbeitet 21.11.2024 09:26:09
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enabled on a device, it introduces the possibility of the host being used for amplification/reflection traffic generation because it w...
CVE-2023-25774
- EPSS 0.07%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:10
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to tr...
CVE-2023-27395
- EPSS 0.43%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:52:49
A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a ...
CVE-2023-27516
- EPSS 0.05%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:53:04
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger th...
CVE-2023-31192
- EPSS 0.4%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 04.11.2025 20:16:26
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack t...