İçeriğe atla
Noroxi

tor kayıtları

tor üreticisine ait 57 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%93
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

57 kayıt
  • CVE-2010-1676
    42Planlayın

    Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (da

    KritikCVSS 10,0İstismar yokEPSS %8

    tor · tor21 Ara 2010

  • CVE-2009-0414
    41Planlayın

    Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.

    KritikCVSS 10,0İstismar yokEPSS %3

    tor · tor3 Şub 2009

  • CVE-2009-0939
    41Planlayın

    Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as

    KritikCVSS 10,0İstismar yokEPSS %2

    tor · tor17 Mar 2009

  • CVE-2008-5398
    38İzleyin

    Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay is

    KritikCVSS 9,3İstismar yokEPSS %2

    tor · tor8 Ara 2008

  • CVE-2011-2778
    31İzleyin

    Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possi

    YüksekCVSS 7,6İstismar yokEPSS %4

    tor · tor22 Ara 2011

  • CVE-2006-3409
    31İzleyin

    Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer

    YüksekCVSS 7,5İstismar yokEPSS %4

    tor · tor6 Tem 2006

  • CVE-2011-0427
    28İzleyin

    Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (me

    OrtaCVSS 6,8İstismar yokEPSS %4

    tor · tor19 Oca 2011

  • CVE-2008-5397
    28İzleyin

    Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privil

    YüksekCVSS 7,2İstismar yokEPSS %0

    tor · tor8 Ara 2008

  • CVE-2007-4097
    26İzleyin

    Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitiv

    OrtaCVSS 6,4İstismar yokEPSS %2

    tor · tor30 Tem 2007

  • CVE-2006-3412
    26İzleyin

    Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restriction

    OrtaCVSS 6,4İstismar yokEPSS %2

    tor · tor6 Tem 2006

  • CVE-2006-3417
    26İzleyin

    Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over

    OrtaCVSS 6,4İstismar yokEPSS %2

    tor · tor6 Tem 2006

  • CVE-2006-3415
    26İzleyin

    Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM

    OrtaCVSS 6,4İstismar yokEPSS %2

    tor · tor6 Tem 2006

  • CVE-2007-4174
    25İzleyin

    Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers

    OrtaCVSS 5,8Kavram kanıtıEPSS %6

    tor · tor7 Ağu 2007

  • CVE-2006-3407
    25İzleyin

    Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

    OrtaCVSS 6,4İstismar yokEPSS %2

    tor · tor6 Tem 2006

  • CVE-2006-3411
    25İzleyin

    TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fo

    OrtaCVSS 6,4İstismar yokEPSS %1

    tor · tor6 Tem 2006

  • CVE-2007-4096
    24İzleyin

    Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified ve

    OrtaCVSS 5,8İstismar yokEPSS %2

    tor · tor30 Tem 2007

  • CVE-2007-4099
    24İzleyin

    Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with

    OrtaCVSS 5,8İstismar yokEPSS %2

    tor · tor30 Tem 2007

  • CVE-2007-4098
    24İzleyin

    Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor

    OrtaCVSS 5,8İstismar yokEPSS %2

    tor · tor30 Tem 2007

  • CVE-2011-2768
    23İzleyin

    Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows

    OrtaCVSS 5,8İstismar yokEPSS %1

    tor · tor22 Ara 2011

  • CVE-2011-0015
    21İzleyin

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allow

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor19 Oca 2011

  • CVE-2006-0414
    21İzleyin

    Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor25 Oca 2006

  • CVE-2011-1924
    21İzleyin

    Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servic

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor14 Haz 2011

  • CVE-2012-3517
    21İzleyin

    Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via ve

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor25 Ağu 2012

  • CVE-2012-3518
    21İzleyin

    The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, w

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor25 Ağu 2012

  • CVE-2011-0492
    21İzleyin

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exi

    OrtaCVSS 5,0İstismar yokEPSS %3

    tor · tor19 Oca 2011