Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Stunnel

First CVE: Feb 12, 2001Active for: 25 yearsTotal CVEs: 12
40.3
VTI Score
Medium

Stunnel is a widely embedded TLS/SSL tunneling proxy that sits in the network path of many applications and services, despite maintaining a single focused product line. Its vulnerability profile centers on certificate validation, access control, and memory-safety issues that recur in protocol parsing and credential handling, and the vendor's disclosures have a tendency to acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Stunnel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Feb 23, 2021
1,977 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-0002HIGH
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
Jan 31, 20027.536NOYES
CVE-2001-0060HIGH
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.
Feb 12, 200110.031NONO
CVE-2011-2940HIGH
stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Aug 25, 20119.330NONO
CVE-2021-20230HIGH
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an a
Feb 23, 20217.524NONO
CVE-2003-0740MEDIUM
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.
Oct 20, 20034.621NOYES
CVE-2014-0016MEDIUM
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the s
Mar 24, 20144.319NONO
CVE-2013-1762MEDIUM
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers t
Mar 8, 20136.618NONO
CVE-2008-2420MEDIUM
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by u
May 23, 20086.818NONO
CVE-2008-2400HIGH
Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vectors.
May 22, 20087.218NONO
CVE-2015-3644MEDIUM
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers t
May 14, 20155.817NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
50%
42%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (8.3%)
Unknown11 (91.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (8.3%)
High0 (0.0%)
Unknown11 (91.7%)
User Interaction
None1 (8.3%)
Unknown11 (91.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (8.3%)
Unknown11 (91.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Stunnel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Stunnel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Stunnel's Products

View all 2 CNAs →

Top CWEs