Known Vulnerabilities for products from Stunnel
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Stunnel".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-20230 | A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both ... | 7.5 - HIGH | 2021-02-23 | 2022-06-01 |
| CVE-2015-3644 | Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after ... | 5.8 - MEDIUM | 2015-05-14 | 2016-12-28 |
| CVE-2014-0016 | stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number genera... | 4.3 - MEDIUM | 2014-03-24 | 2017-01-26 |
| CVE-2013-1762 | stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform ... | 6.6 - MEDIUM | 2013-03-08 | 2014-01-17 |
| CVE-2011-2940 | stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup... | 9.3 - HIGH | 2011-08-25 | 2017-08-29 |
| CVE-2008-2420 | The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remot... | 6.8 - MEDIUM | 2008-05-23 | 2017-08-08 |
| CVE-2008-2400 | Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges... | 7.2 - HIGH | 2008-05-22 | 2017-08-08 |
| CVE-2003-0740 | Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hija... | 4.6 - MEDIUM | 2003-10-20 | 2016-10-18 |
| CVE-2003-0147 | OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by d... | 5 - MEDIUM | 2003-03-31 | 2018-10-19 |
| CVE-2002-1563 | stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions th... | 1.2 - LOW | 2003-05-12 | 2016-10-18 |
| CVE-2002-0002 | Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote ... | 7.5 - HIGH | 2002-01-31 | 2017-10-10 |
| CVE-2001-0060 | Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident u... | 10 - HIGH | 2001-02-12 | 2018-05-03 |
Known software with vulnerabilities from Stunnel
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Stunnel | Stunnel | 0.1 |