Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2007-3165 Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of tr… Tor Patch available Fix from $1,6002007-06-11 MEDIUM 5.0 CVE-2006-6893 Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CP… Tor No fix yet Fix from $1,6002006-12-31 HIGH 7.5 CVE-2006-3409 Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow… Tor Patch available Fix from $1,9502006-07-07 MEDIUM 6.4 CVE-2006-3407 Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters. Tor Patch available Fix from $1,6002006-07-07 MEDIUM 6.4 CVE-2006-3411 TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote … Tor Patch available Fix from $1,6002006-07-07 MEDIUM 6.4 CVE-2006-3412 Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dir… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 6.4 CVE-2006-3415 Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack … Tor Patch available Fix from $1,6002006-07-07 MEDIUM 6.4 CVE-2006-3417 Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes th… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3408 Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of servic… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3410 Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unsp… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3413 The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain pote… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3414 Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group us… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3416 Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while thi… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3418 Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof th… Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-3419 Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value … Tor Patch available Fix from $1,6002006-07-07 MEDIUM 5.0 CVE-2006-0414 Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hi… Tor Patch available Fix from $1,6002006-01-25 MEDIUM 5.0 CVE-2005-2643 Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman … Tor Patch available Fix from $1,6002005-08-23 MEDIUM 5.0 CVE-2005-2050 Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's pro… Tor Patch available Fix from $1,6002005-06-28