Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown
CVE-2011-2778
Disclosure Date: December 23, 2011 (last updated October 04, 2023)
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by (1) establishing a SOCKS connection to SocksPort or (2) leveraging a SOCKS proxy configuration.
0
Attacker Value
Unknown
CVE-2011-4895
Disclosure Date: December 23, 2011 (last updated October 04, 2023)
Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.
0
Attacker Value
Unknown
CVE-2011-2768
Disclosure Date: December 23, 2011 (last updated October 04, 2023)
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.
0
Attacker Value
Unknown
CVE-2011-1924
Disclosure Date: June 14, 2011 (last updated October 04, 2023)
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
0
Attacker Value
Unknown
CVE-2011-1828
Disclosure Date: May 16, 2011 (last updated October 04, 2023)
usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.
0
Attacker Value
Unknown
CVE-2011-1842
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.
0
Attacker Value
Unknown
CVE-2011-0729
Disclosure Date: April 29, 2011 (last updated October 04, 2023)
dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.
0
Attacker Value
Unknown
CVE-2011-0490
Disclosure Date: January 19, 2011 (last updated October 04, 2023)
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denial of service (daemon crash) via vectors that trigger certain log messages.
0
Attacker Value
Unknown
CVE-2011-0493
Disclosure Date: January 19, 2011 (last updated October 04, 2023)
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
0
Attacker Value
Unknown
CVE-2011-0491
Disclosure Date: January 19, 2011 (last updated October 04, 2023)
The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors, related to "underflow errors."
0