Back

CVE-2002-0002

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

Published: Jan 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (25)

Vendor Product Version
stunnel stunnel 3.3
stunnel stunnel 3.4a
stunnel stunnel 3.7
stunnel stunnel 3.8
stunnel stunnel 3.9
stunnel stunnel 3.10
stunnel stunnel 3.11
stunnel stunnel 3.12
stunnel stunnel 3.13
stunnel stunnel 3.14
stunnel stunnel 3.15
stunnel stunnel 3.16
stunnel stunnel 3.17
stunnel stunnel 3.18
stunnel stunnel 3.19
stunnel stunnel 3.20
stunnel stunnel 3.21
stunnel stunnel 3.21a
stunnel stunnel 3.21b
stunnel stunnel 3.21c

…and 5 more

GitHub Security Advisory GHSA-8qj7-vx74-c666

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 5.28%

Top 8% most likely to be exploited

Threat Score 31.6 / 100

Data Sources

NVD EPSS GitHub