Stonesoft develops a narrowly focused portfolio of security appliances and clustering solutions, including products such as StoneGate, ServerCluster, and StoneBeat variants, that serve as network security gateways and management platforms. The vendor's vulnerability exposure centers on access-control weaknesses, memory-safety issues including NULL-pointer dereferences and out-of-bounds reads, and parsing problems that recur across its appliance and clustering product lines. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stonesoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2009-2631MEDIUM Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access | Dec 4, 2009 | 6.8 | 22 | NO | NO |
CVE-2007-5793HIGH Stonesoft StoneGate IPS before 4.0 does not properly decode Fullwidth/Halfwidth Unicode encoded data, which makes it easier for remote attackers to scan or penetrate systems and av | Nov 1, 2007 | 7.1 | 19 | NO | NO |
CVE-2004-0498MEDIUM The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets. | Dec 31, 2004 | 5.0 | 19 | NO | NO |
CVE-2004-0081MEDIUM OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co | Nov 23, 2004 | 5.0 | 18 | NO | NO |
CVE-2005-3672MEDIUM The Internet Key Exchange version 1 (IKEv1) implementation in Stonesoft StoneGate Firewall before 2.6.1 allows remote attackers to cause a denial of service via certain crafted IKE | Nov 18, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stonesoft.
Media articles that mention a CVE ID that affects a product developed by Stonesoft — matched by CVE ID, not by vendor name.