tor kayıtları
tor üreticisine ait 57 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %93
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-189 Numeric Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
57 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2010-1676İstismar yok | Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (dator · tor · CWE-119 | Kritik10,0 | — | %7,9 | 21 Ara 2010 |
41Planlayın | CVE-2009-0414İstismar yok | Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.tor · tor · CWE-399 | Kritik10,0 | — | %3,0 | 3 Şub 2009 |
41Planlayın | CVE-2009-0939İstismar yok | Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," astor · tor | Kritik10,0 | — | %2,1 | 17 Mar 2009 |
38İzleyin | CVE-2008-5398İstismar yok | Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay istor · tor · CWE-264 | Kritik9,3 | — | %2,0 | 8 Ara 2008 |
31İzleyin | CVE-2011-2778İstismar yok | Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possitor · tor · CWE-119 | Yüksek7,6 | — | %3,8 | 22 Ara 2011 |
31İzleyin | CVE-2006-3409İstismar yok | Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffertor · tor | Yüksek7,5 | — | %3,7 | 6 Tem 2006 |
28İzleyin | CVE-2011-0427İstismar yok | Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (metor · tor · CWE-119 | Orta6,8 | — | %4,4 | 19 Oca 2011 |
28İzleyin | CVE-2008-5397İstismar yok | Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain priviltor · tor · CWE-264 | Yüksek7,2 | — | %0,4 | 8 Ara 2008 |
26İzleyin | CVE-2007-4097İstismar yok | Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitivtor · tor | Orta6,4 | — | %2,2 | 30 Tem 2007 |
26İzleyin | CVE-2006-3412İstismar yok | Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictiontor · tor | Orta6,4 | — | %2,2 | 6 Tem 2006 |
26İzleyin | CVE-2006-3417İstismar yok | Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred overtor · tor | Orta6,4 | — | %2,1 | 6 Tem 2006 |
26İzleyin | CVE-2006-3415İstismar yok | Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITMtor · tor | Orta6,4 | — | %2,0 | 6 Tem 2006 |
25İzleyin | CVE-2007-4174Kavram kanıtı | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers tor · tor · CWE-264 | Orta5,8 | — | %6,2 | 7 Ağu 2007 |
25İzleyin | CVE-2006-3407İstismar yok | Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.tor · tor | Orta6,4 | — | %1,5 | 6 Tem 2006 |
25İzleyin | CVE-2006-3411İstismar yok | TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fotor · tor | Orta6,4 | — | %1,3 | 6 Tem 2006 |
24İzleyin | CVE-2007-4096İstismar yok | Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vetor · tor | Orta5,8 | — | %2,0 | 30 Tem 2007 |
24İzleyin | CVE-2007-4099İstismar yok | Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers withtor · tor | Orta5,8 | — | %1,9 | 30 Tem 2007 |
24İzleyin | CVE-2007-4098İstismar yok | Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tortor · tor | Orta5,8 | — | %1,9 | 30 Tem 2007 |
23İzleyin | CVE-2011-2768İstismar yok | Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allowstor · tor · CWE-264 | Orta5,8 | — | %0,7 | 22 Ara 2011 |
21İzleyin | CVE-2011-0015İstismar yok | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allowtor · tor · CWE-20 | Orta5,0 | — | %3,1 | 19 Oca 2011 |
21İzleyin | CVE-2006-0414İstismar yok | Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses tor · tor | Orta5,0 | — | %3,0 | 25 Oca 2006 |
21İzleyin | CVE-2011-1924İstismar yok | Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servictor · tor · CWE-119 | Orta5,0 | — | %2,8 | 14 Haz 2011 |
21İzleyin | CVE-2012-3517İstismar yok | Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vetor · tor · CWE-399 | Orta5,0 | — | %2,8 | 25 Ağu 2012 |
21İzleyin | CVE-2012-3518İstismar yok | The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, wtor · tor · CWE-119 | Orta5,0 | — | %2,8 | 25 Ağu 2012 |
21İzleyin | CVE-2011-0492İstismar yok | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exitor · tor · CWE-399 | Orta5,0 | — | %2,5 | 19 Oca 2011 |
- CVE-2010-167642Planlayın
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (da
KritikCVSS 10,0İstismar yokEPSS %8tor · tor21 Ara 2010
- CVE-2009-041441Planlayın
Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
KritikCVSS 10,0İstismar yokEPSS %3tor · tor3 Şub 2009
- CVE-2009-093941Planlayın
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as
KritikCVSS 10,0İstismar yokEPSS %2tor · tor17 Mar 2009
- CVE-2008-539838İzleyin
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay is
KritikCVSS 9,3İstismar yokEPSS %2tor · tor8 Ara 2008
- CVE-2011-277831İzleyin
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possi
YüksekCVSS 7,6İstismar yokEPSS %4tor · tor22 Ara 2011
- CVE-2006-340931İzleyin
Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer
YüksekCVSS 7,5İstismar yokEPSS %4tor · tor6 Tem 2006
- CVE-2011-042728İzleyin
Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (me
OrtaCVSS 6,8İstismar yokEPSS %4tor · tor19 Oca 2011
- CVE-2008-539728İzleyin
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privil
YüksekCVSS 7,2İstismar yokEPSS %0tor · tor8 Ara 2008
- CVE-2007-409726İzleyin
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitiv
OrtaCVSS 6,4İstismar yokEPSS %2tor · tor30 Tem 2007
- CVE-2006-341226İzleyin
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restriction
OrtaCVSS 6,4İstismar yokEPSS %2tor · tor6 Tem 2006
- CVE-2006-341726İzleyin
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over
OrtaCVSS 6,4İstismar yokEPSS %2tor · tor6 Tem 2006
- CVE-2006-341526İzleyin
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM
OrtaCVSS 6,4İstismar yokEPSS %2tor · tor6 Tem 2006
- CVE-2007-417425İzleyin
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers
OrtaCVSS 5,8Kavram kanıtıEPSS %6tor · tor7 Ağu 2007
- CVE-2006-340725İzleyin
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
OrtaCVSS 6,4İstismar yokEPSS %2tor · tor6 Tem 2006
- CVE-2006-341125İzleyin
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fo
OrtaCVSS 6,4İstismar yokEPSS %1tor · tor6 Tem 2006
- CVE-2007-409624İzleyin
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified ve
OrtaCVSS 5,8İstismar yokEPSS %2tor · tor30 Tem 2007
- CVE-2007-409924İzleyin
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with
OrtaCVSS 5,8İstismar yokEPSS %2tor · tor30 Tem 2007
- CVE-2007-409824İzleyin
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor
OrtaCVSS 5,8İstismar yokEPSS %2tor · tor30 Tem 2007
- CVE-2011-276823İzleyin
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows
OrtaCVSS 5,8İstismar yokEPSS %1tor · tor22 Ara 2011
- CVE-2011-001521İzleyin
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allow
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor19 Oca 2011
- CVE-2006-041421İzleyin
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor25 Oca 2006
- CVE-2011-192421İzleyin
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servic
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor14 Haz 2011
- CVE-2012-351721İzleyin
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via ve
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor25 Ağu 2012
- CVE-2012-351821İzleyin
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, w
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor25 Ağu 2012
- CVE-2011-049221İzleyin
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exi
OrtaCVSS 5,0İstismar yokEPSS %3tor · tor19 Oca 2011