Gnutls

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

75
Total CVEs
More Total CVEs than 99% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gnutls over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
May 18, 2026
67 days ago

CVE Severity & Scoring

Gnutls75 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.3%)
Network36 (48.0%)
Unknown37 (49.3%)
Physical1 (1.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (34.7%)
High12 (16.0%)
Unknown37 (49.3%)
User Interaction
None38 (50.7%)
Unknown37 (49.3%)
Required0 (0.0%)
Privileges Required
Low3 (4.0%)
High0 (0.0%)
None35 (46.7%)
Unknown37 (49.3%)

Top CVEs

Signals from CVEs in this product scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier,
Nov 9, 20099.885NOYES
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server appl
Mar 27, 20197.557NONO
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated username
May 7, 20269.842NONO
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-o
Apr 30, 20269.140NONO
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted
Mar 24, 20179.840NONO
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-i
Mar 7, 20145.838NONO
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact vi
Mar 13, 20127.536NOYES
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible f
May 18, 20267.535NONO
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Nam
Apr 30, 20267.434NONO
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impa
Mar 24, 20179.834NONO

Exploit Exposure

Signals from CVEs in this product scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
5.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (75 CVEs).

Media Mentions

Signals from CVEs in this product scope (75 CVEs).

Top CNAs Publishing CVEs For Gnutls

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.6.8-11.el8_217.41.4%00
3.5.749.213.5%00
3.5.649.213.5%00
3.5.549.213.5%00
3.5.449.213.5%00
3.5.358.911.3%00
3.5.258.911.3%00
3.5.158.911.3%00
3.5.058.911.3%00
3.4.315.019.0%00
3.4.215.019.0%00
3.4.1217.52.2%00
3.4.115.019.0%00
3.4.015.019.0%00
3.3.925.011.2%00
3.3.825.011.2%00
3.3.725.011.2%00
3.3.625.011.2%00
3.3.525.011.2%00
3.3.425.011.2%00