Перейти к содержимому
Noroxi

Записи tor

57 опубликованных записей вендора tor.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
93 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

57 записей
  • CVE-2010-1676
    42В плане

    Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (da

    КритическаяCVSS 10,0Эксплойта нетEPSS 8 %

    tor · tor21 дек. 2010 г.

  • CVE-2009-0414
    41В плане

    Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    tor · tor3 февр. 2009 г.

  • CVE-2009-0939
    41В плане

    Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    tor · tor17 мар. 2009 г.

  • CVE-2008-5398
    38Наблюдать

    Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay is

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    tor · tor8 дек. 2008 г.

  • CVE-2011-2778
    31Наблюдать

    Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possi

    ВысокаяCVSS 7,6Эксплойта нетEPSS 4 %

    tor · tor22 дек. 2011 г.

  • CVE-2006-3409
    31Наблюдать

    Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    tor · tor6 июл. 2006 г.

  • CVE-2011-0427
    28Наблюдать

    Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (me

    СредняяCVSS 6,8Эксплойта нетEPSS 4 %

    tor · tor19 янв. 2011 г.

  • CVE-2008-5397
    28Наблюдать

    Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privil

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    tor · tor8 дек. 2008 г.

  • CVE-2007-4097
    26Наблюдать

    Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitiv

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    tor · tor30 июл. 2007 г.

  • CVE-2006-3412
    26Наблюдать

    Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restriction

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    tor · tor6 июл. 2006 г.

  • CVE-2006-3417
    26Наблюдать

    Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    tor · tor6 июл. 2006 г.

  • CVE-2006-3415
    26Наблюдать

    Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    tor · tor6 июл. 2006 г.

  • CVE-2007-4174
    25Наблюдать

    Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers

    СредняяCVSS 5,8Proof of conceptEPSS 6 %

    tor · tor7 авг. 2007 г.

  • CVE-2006-3407
    25Наблюдать

    Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    tor · tor6 июл. 2006 г.

  • CVE-2006-3411
    25Наблюдать

    TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fo

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    tor · tor6 июл. 2006 г.

  • CVE-2007-4096
    24Наблюдать

    Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified ve

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    tor · tor30 июл. 2007 г.

  • CVE-2007-4099
    24Наблюдать

    Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    tor · tor30 июл. 2007 г.

  • CVE-2007-4098
    24Наблюдать

    Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    tor · tor30 июл. 2007 г.

  • CVE-2011-2768
    23Наблюдать

    Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows

    СредняяCVSS 5,8Эксплойта нетEPSS 1 %

    tor · tor22 дек. 2011 г.

  • CVE-2011-0015
    21Наблюдать

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allow

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor19 янв. 2011 г.

  • CVE-2006-0414
    21Наблюдать

    Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor25 янв. 2006 г.

  • CVE-2011-1924
    21Наблюдать

    Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servic

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor14 июн. 2011 г.

  • CVE-2012-3517
    21Наблюдать

    Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via ve

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor25 авг. 2012 г.

  • CVE-2012-3518
    21Наблюдать

    The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, w

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor25 авг. 2012 г.

  • CVE-2011-0492
    21Наблюдать

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exi

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    tor · tor19 янв. 2011 г.