threat
engine
.sh
Back
·
··:··
Home
/
Product
/
stunnel
Product
stunnel
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2021-20230
< 5.57
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redir
7.5
HIGH
CVE-2015-3644
all versions
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the i
CVE-2014-0016
<= 4.56
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (
CVE-2013-1762
<= 4.54
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integ
CVE-2011-2940
all versions
stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)
CVE-2008-2420
all versions
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote att
CVE-2008-2400
all versions
Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via
CVE-2003-0740
all versions
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack th
CVE-2002-1563
all versions
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that ca
CVE-2003-0147
all versions
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determ
CVE-2002-0002
all versions
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malic
CVE-2001-0060
all versions
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident userna
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin