Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:deb/debian/openvpn

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

Join the discussion

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

Join the discussion

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

Join the discussion

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

Join the discussion

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

Join the discussion

CVE-2023-46850 is a use-after-free vulnerability in OpenVPN Community Edition versions 2.6.0 through 2.6.6. This flaw arises when network buffers are sent to a remote peer, potentially causing undefined behavior, memory leaks, or remote code execution. Exploitation does not require authentication but involves network interaction with a vulnerable OpenVPN server or client. Although no known exploits are currently reported in the wild, successful exploitation could compromise confidentiality, integrity, and availability of VPN communications. European organizations relying on OpenVPN for secure remote access and site-to-site VPNs are at risk, especially critical infrastructure and enterprises with high VPN usage. Mitigation involves promptly updating to patched versions once available, employing network-level filtering to restrict OpenVPN traffic, and monitoring for anomalous VPN behavior.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:deb/debian/openvpn
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses