Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openconnect MEDIUM 5.9
CVE-2020-12105

OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-mid…

Fix: after 8.08
Fix from $1,600 2020-04-23
Openconnect CRITICAL 9.8
CVE-2013-7098

OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.

Fix: 5.02+
Fix from $2,300 2020-02-13
Openconnect MEDIUM 5.0
CVE-2012-6128

Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash)…

Fix: after 4.07
Fix from $1,600 2013-02-24
Openconnect HIGH 7.8
CVE-2012-3291

Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.

Fix: after 3.17
Fix from $1,950 2012-06-07
Openconnect MEDIUM 6.4
CVE-2010-3901

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN…

Fix: after 2.22
Fix from $1,600 2010-10-14
Openconnect MEDIUM 5.0
CVE-2010-3902

OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by…

Fix: after 2.25
Fix from $1,600 2010-10-14
Openconnect MEDIUM 5.0
CVE-2010-3903

Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a …

Fix: after 2.22
Fix from $1,600 2010-10-14
Openconnect MEDIUM 5.0
CVE-2009-5009

Double free vulnerability in OpenConnect before 1.40 might allow remote AnyConnect SSL VPN servers to cause a denial of service (application crash) o…

Fix: after 1.30
Fix from $1,600 2010-10-14