peter bassill · operator
$ cve CVE-2002-0002 JSON

CVE-2002-0002 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 5.3% (pctl 92)

Patch early

A public exploit exists.

Description

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS5.28% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2002-01-31
Last modified2026-06-16

Affected (4)

VendorProduct
engardelinuxsecure linux
mandrakesoftmandrake linux
redhatlinux
stunnelstunnel

Public exploits

SourceTitleDate
exploit-dbSTunnel 3.x - Client Negotiation Protocol Format String2001-12-22

References

→ the Explorer  ·  watch your stack  ·  NVD