CVE Tools

Stonesoft

4 CVEs tracked since 2004. Since Mar 2004, none of them reached CISA KEV.

Stonesoft CVEs per month

Mar 2004 to Sep 2005. Point at a month, or focus the strip and use the arrow keys.
Stonesoft CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2004-0330
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-0910

Products

The products that kept showing up in Stonesoft's monthly top three, with their CVEs summed over those months.

  1. Servercluster31 month
  2. Stonebeat Fullcluster31 month
  3. Stonebeat Securitycluster31 month
  4. Firewall Engine11 month

Latest CVEs

The 7 most recently published vulnerabilities affecting Stonesoft.

  1. CVE-2009-2631Clientless SSL VPN products break web browser domain-based security models6.8
  2. CVE-2007-5793Stonesoft StoneGate IPS before 4.0 does not properly decode Fullwidth/Halfwidth Unicode encoded data, which makes it easier for remote attackers to scan or penetrate systems and avoid detection.7.1
  3. CVE-2005-3672The Internet Key Exchange version 1 (IKEv1) implementation in Stonesoft StoneGate Firewall before 2.6.1 allows remote attackers to cause a denial of service via certain crafted IKE packets, as demo...5.0
  4. CVE-2004-0498The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.5.0
  5. CVE-2004-0081OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Tes...5.0
  6. CVE-2004-0112The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote ...5.0
  7. CVE-2004-0079The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a nu...7.5

The record

Peak rank
#27 in Mar 2004
Busiest month shown
Mar 2004, 3 CVEs
Months with a KEV entry
0 since Mar 2004
Monthly snapshots
2 since 2004
Stonesoft's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store