Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Stunnel HIGH 7.5
CVE-2021-20230

A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain…

Fix: 5.57+
Fix from $1,950 2021-02-23
Stunnel MEDIUM 5.8
CVE-2015-3644

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, …

Patch available
Fix from $1,600 2015-05-14
Stunnel MEDIUM 6.6
CVE-2013-1762

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, whic…

Fix: after 4.54
Fix from $1,600 2013-03-08
Stunnel HIGH 9.3
CVE-2011-2940EPSS 6%

stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve…

Mitigation only
Fix from $1,950 2011-08-25
Stunnel MEDIUM 6.8
CVE-2008-2420

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass in…

Patch available
Fix from $1,600 2008-05-23
Stunnel HIGH 7.2
CVE-2008-2400

Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vect…

Mitigation only
Fix from $1,950 2008-05-22
Stunnel HIGH 10.0
CVE-2001-0060

Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.

Patch available
Fix from $1,950 2001-02-12