Vulnerability index

Browse CVEs

71 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-46850 Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buff… Openvpn 2.12.2+ Fix from $2,3002023-11-11 HIGH 7.5 CVE-2023-46849 Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour w… Openvpn after 2.11.3 Fix from $1,9502023-11-11 MEDIUM 5.9 CVE-2022-3761 OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept co… Connect 3.4.0.3121 / 3.4.0.4506+ Fix from $1,6002023-10-17 HIGH 7.5 CVE-2020-20813 Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. Openvpn after 2.4.7 Fix from $1,9502023-08-22 HIGH 7.5 CVE-2021-4234 OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client whic… Openvpn Access Server 2.11.0+ Fix from $1,9502022-07-06 HIGH 7.5 CVE-2022-33737 The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random genera… Openvpn Access Server 2.11.0+ Fix from $1,9502022-07-06 HIGH 7.5 CVE-2022-33738 OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal Openvpn Access Server 2.11.0+ Fix from $1,9502022-07-06 CRITICAL 9.8 CVE-2022-0547 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def… Openvpn 2.4.12 / 2.5.6+ Fix from $2,3002022-03-18 MEDIUM 6.1 CVE-2021-3824 OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL. Openvpn Access Server after 2.9.4 Fix from $1,6002021-09-23 HIGH 7.4 CVE-2021-3547 OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated ser… Openvpn Patch available Fix from $1,9502021-07-12 HIGH 7.8 CVE-2021-3613 OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, whi… Connect after 3.3.0 Fix from $1,9502021-07-02 HIGH 7.8 CVE-2021-3606 OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present,… Openvpn 2.5.3+ Fix from $1,9502021-07-02 HIGH 7.5 CVE-2020-36382 OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication t… Openvpn Access Server after 2.8.7 Fix from $1,9502021-06-04 MEDIUM 5.3 CVE-2020-15077 OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers config… Openvpn Access Server after 2.8.7 Fix from $1,6002021-06-04 HIGH 7.8 CVE-2020-15076 Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp. Private Tunnel after 3.0.1 Fix from $1,9502021-05-26 HIGH 7.5 CVE-2020-15078 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with defe… Openvpn 2.4.11 / 2.5.2+ Fix from $1,9502021-04-26 HIGH 7.1 CVE-2020-15075 OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp. Connect after 3.2.6 Fix from $1,9502021-03-30 HIGH 7.5 CVE-2020-15074 OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconn… Openvpn Access Server 2.8.4 / 2.9.6+ Fix from $1,9502020-07-14 HIGH 7.5 CVE-2020-11462 An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible t… Openvpn Access Server 2.7.0+ Fix from $1,9502020-05-04 HIGH 7.8 CVE-2020-9442 OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to … Connect after 3.1.0.361 Fix from $1,9502020-02-28 CRITICAL 9.8 CVE-2020-8953 OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication). Openvpn Access Server 2.8.1+ Fix from $2,3002020-02-13 HIGH 7.8 CVE-2018-9336 openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sendin… Openvpn 2.4.6+ Fix from $1,9502018-05-01 CRITICAL 9.1 CVE-2018-7544 A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without… Openvpn after 2.4.5 Fix from $2,3002018-03-16 CRITICAL 9.8 CVE-2017-12166 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting … Openvpn 2.3.18 / 2.4.4+ Fix from $2,3002017-10-04 HIGH 7.5 CVE-2017-7508 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6 packet. Openvpn after 2.3.16 Fix from $1,9502017-06-27 HIGH 7.4 CVE-2017-7520 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-mid… Openvpn after 2.3.16 Fix from $1,9502017-06-27 MEDIUM 6.5 CVE-2017-7522EPSS 6% OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with a… Openvpn after 2.3.16 Fix from $1,6002017-06-27 MEDIUM 5.9 CVE-2017-7521 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double… Openvpn after 2.3.16 Fix from $1,6002017-06-27 MEDIUM 6.1 CVE-2017-5868 CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequ… Openvpn Access Server No fix yet Fix from $1,6002017-05-26 HIGH 7.5 CVE-2017-7478EPSS 14% OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue… Openvpn No fix yet Fix from $1,9502017-05-15