Stunnel is a widely embedded TLS/SSL tunneling proxy that sits in the network path of many applications and services, despite maintaining a single focused product line. Its vulnerability profile centers on certificate validation, access control, and memory-safety issues that recur in protocol parsing and credential handling, and the vendor's disclosures have a tendency to acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stunnel over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0002HIGH Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. | Jan 31, 2002 | 7.5 | 36 | NO | YES |
CVE-2001-0060HIGH Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username. | Feb 12, 2001 | 10.0 | 31 | NO | NO |
CVE-2011-2940HIGH stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. | Aug 25, 2011 | 9.3 | 30 | NO | NO |
CVE-2021-20230HIGH A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an a | Feb 23, 2021 | 7.5 | 24 | NO | NO |
CVE-2003-0740MEDIUM Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server. | Oct 20, 2003 | 4.6 | 21 | NO | YES |
CVE-2014-0016MEDIUM stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the s | Mar 24, 2014 | 4.3 | 19 | NO | NO |
CVE-2013-1762MEDIUM stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers t | Mar 8, 2013 | 6.6 | 18 | NO | NO |
CVE-2008-2420MEDIUM The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by u | May 23, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-2400HIGH Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vectors. | May 22, 2008 | 7.2 | 18 | NO | NO |
CVE-2015-3644MEDIUM Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers t | May 14, 2015 | 5.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stunnel.
Media articles that mention a CVE ID that affects a product developed by Stunnel — matched by CVE ID, not by vendor name.