Home/Product/stunnel
Product

stunnel

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-20230
< 5.57
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redir
7.5HIGH
CVE-2015-3644
all versions
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the i
CVE-2014-0016
<= 4.56
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (
CVE-2013-1762
<= 4.54
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integ
CVE-2011-2940
all versions
stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)
CVE-2008-2420
all versions
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote att
CVE-2008-2400
all versions
Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via
CVE-2003-0740
all versions
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack th
CVE-2002-1563
all versions
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that ca
CVE-2003-0147
all versions
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determ
CVE-2002-0002
all versions
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malic
CVE-2001-0060
all versions
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident userna
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin