Записи tor
57 опубликованных записей вендора tor.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 93 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-189 Numeric Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2010-1676Эксплойта нет | Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (dator · tor · CWE-119 | Критическая10,0 | — | 7,9 % | 21 дек. 2010 г. |
41В плане | CVE-2009-0414Эксплойта нет | Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.tor · tor · CWE-399 | Критическая10,0 | — | 3,0 % | 3 февр. 2009 г. |
41В плане | CVE-2009-0939Эксплойта нет | Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," astor · tor | Критическая10,0 | — | 2,1 % | 17 мар. 2009 г. |
38Наблюдать | CVE-2008-5398Эксплойта нет | Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay istor · tor · CWE-264 | Критическая9,3 | — | 2,0 % | 8 дек. 2008 г. |
31Наблюдать | CVE-2011-2778Эксплойта нет | Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possitor · tor · CWE-119 | Высокая7,6 | — | 3,8 % | 22 дек. 2011 г. |
31Наблюдать | CVE-2006-3409Эксплойта нет | Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffertor · tor | Высокая7,5 | — | 3,7 % | 6 июл. 2006 г. |
28Наблюдать | CVE-2011-0427Эксплойта нет | Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (metor · tor · CWE-119 | Средняя6,8 | — | 4,4 % | 19 янв. 2011 г. |
28Наблюдать | CVE-2008-5397Эксплойта нет | Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain priviltor · tor · CWE-264 | Высокая7,2 | — | 0,4 % | 8 дек. 2008 г. |
26Наблюдать | CVE-2007-4097Эксплойта нет | Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitivtor · tor | Средняя6,4 | — | 2,2 % | 30 июл. 2007 г. |
26Наблюдать | CVE-2006-3412Эксплойта нет | Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictiontor · tor | Средняя6,4 | — | 2,2 % | 6 июл. 2006 г. |
26Наблюдать | CVE-2006-3417Эксплойта нет | Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred overtor · tor | Средняя6,4 | — | 2,1 % | 6 июл. 2006 г. |
26Наблюдать | CVE-2006-3415Эксплойта нет | Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITMtor · tor | Средняя6,4 | — | 2,0 % | 6 июл. 2006 г. |
25Наблюдать | CVE-2007-4174Proof of concept | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers tor · tor · CWE-264 | Средняя5,8 | — | 6,2 % | 7 авг. 2007 г. |
25Наблюдать | CVE-2006-3407Эксплойта нет | Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.tor · tor | Средняя6,4 | — | 1,5 % | 6 июл. 2006 г. |
25Наблюдать | CVE-2006-3411Эксплойта нет | TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fotor · tor | Средняя6,4 | — | 1,3 % | 6 июл. 2006 г. |
24Наблюдать | CVE-2007-4096Эксплойта нет | Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vetor · tor | Средняя5,8 | — | 2,0 % | 30 июл. 2007 г. |
24Наблюдать | CVE-2007-4099Эксплойта нет | Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers withtor · tor | Средняя5,8 | — | 1,9 % | 30 июл. 2007 г. |
24Наблюдать | CVE-2007-4098Эксплойта нет | Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tortor · tor | Средняя5,8 | — | 1,9 % | 30 июл. 2007 г. |
23Наблюдать | CVE-2011-2768Эксплойта нет | Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allowstor · tor · CWE-264 | Средняя5,8 | — | 0,7 % | 22 дек. 2011 г. |
21Наблюдать | CVE-2011-0015Эксплойта нет | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allowtor · tor · CWE-20 | Средняя5,0 | — | 3,1 % | 19 янв. 2011 г. |
21Наблюдать | CVE-2006-0414Эксплойта нет | Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses tor · tor | Средняя5,0 | — | 3,0 % | 25 янв. 2006 г. |
21Наблюдать | CVE-2011-1924Эксплойта нет | Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servictor · tor · CWE-119 | Средняя5,0 | — | 2,8 % | 14 июн. 2011 г. |
21Наблюдать | CVE-2012-3517Эксплойта нет | Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vetor · tor · CWE-399 | Средняя5,0 | — | 2,8 % | 25 авг. 2012 г. |
21Наблюдать | CVE-2012-3518Эксплойта нет | The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, wtor · tor · CWE-119 | Средняя5,0 | — | 2,8 % | 25 авг. 2012 г. |
21Наблюдать | CVE-2011-0492Эксплойта нет | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exitor · tor · CWE-399 | Средняя5,0 | — | 2,5 % | 19 янв. 2011 г. |
- CVE-2010-167642В плане
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (da
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %tor · tor21 дек. 2010 г.
- CVE-2009-041441В плане
Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %tor · tor3 февр. 2009 г.
- CVE-2009-093941В плане
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %tor · tor17 мар. 2009 г.
- CVE-2008-539838Наблюдать
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay is
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %tor · tor8 дек. 2008 г.
- CVE-2011-277831Наблюдать
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possi
ВысокаяCVSS 7,6Эксплойта нетEPSS 4 %tor · tor22 дек. 2011 г.
- CVE-2006-340931Наблюдать
Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %tor · tor6 июл. 2006 г.
- CVE-2011-042728Наблюдать
Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (me
СредняяCVSS 6,8Эксплойта нетEPSS 4 %tor · tor19 янв. 2011 г.
- CVE-2008-539728Наблюдать
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privil
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %tor · tor8 дек. 2008 г.
- CVE-2007-409726Наблюдать
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitiv
СредняяCVSS 6,4Эксплойта нетEPSS 2 %tor · tor30 июл. 2007 г.
- CVE-2006-341226Наблюдать
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restriction
СредняяCVSS 6,4Эксплойта нетEPSS 2 %tor · tor6 июл. 2006 г.
- CVE-2006-341726Наблюдать
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over
СредняяCVSS 6,4Эксплойта нетEPSS 2 %tor · tor6 июл. 2006 г.
- CVE-2006-341526Наблюдать
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM
СредняяCVSS 6,4Эксплойта нетEPSS 2 %tor · tor6 июл. 2006 г.
- CVE-2007-417425Наблюдать
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers
СредняяCVSS 5,8Proof of conceptEPSS 6 %tor · tor7 авг. 2007 г.
- CVE-2006-340725Наблюдать
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
СредняяCVSS 6,4Эксплойта нетEPSS 2 %tor · tor6 июл. 2006 г.
- CVE-2006-341125Наблюдать
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fo
СредняяCVSS 6,4Эксплойта нетEPSS 1 %tor · tor6 июл. 2006 г.
- CVE-2007-409624Наблюдать
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified ve
СредняяCVSS 5,8Эксплойта нетEPSS 2 %tor · tor30 июл. 2007 г.
- CVE-2007-409924Наблюдать
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with
СредняяCVSS 5,8Эксплойта нетEPSS 2 %tor · tor30 июл. 2007 г.
- CVE-2007-409824Наблюдать
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor
СредняяCVSS 5,8Эксплойта нетEPSS 2 %tor · tor30 июл. 2007 г.
- CVE-2011-276823Наблюдать
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows
СредняяCVSS 5,8Эксплойта нетEPSS 1 %tor · tor22 дек. 2011 г.
- CVE-2011-001521Наблюдать
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allow
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor19 янв. 2011 г.
- CVE-2006-041421Наблюдать
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor25 янв. 2006 г.
- CVE-2011-192421Наблюдать
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servic
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor14 июн. 2011 г.
- CVE-2012-351721Наблюдать
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via ve
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor25 авг. 2012 г.
- CVE-2012-351821Наблюдать
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, w
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor25 авг. 2012 г.
- CVE-2011-049221Наблюдать
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exi
СредняяCVSS 5,0Эксплойта нетEPSS 3 %tor · tor19 янв. 2011 г.