Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2011-0015
Disclosure Date: January 19, 2011 (last updated October 04, 2023)
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.
0
Attacker Value
Unknown
CVE-2010-1676
Disclosure Date: December 22, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-0385
Disclosure Date: January 25, 2010 (last updated October 04, 2023)
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
0
Attacker Value
Unknown
CVE-2010-0383
Disclosure Date: January 25, 2010 (last updated October 04, 2023)
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
0
Attacker Value
Unknown
CVE-2009-0414
Disclosure Date: February 03, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
0
Attacker Value
Unknown
CVE-2008-5398
Disclosure Date: December 09, 2008 (last updated October 04, 2023)
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
0
Attacker Value
Unknown
CVE-2008-5397
Disclosure Date: December 09, 2008 (last updated October 04, 2023)
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
0
Attacker Value
Unknown
CVE-2007-4174
Disclosure Date: August 07, 2007 (last updated October 04, 2023)
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
0
Attacker Value
Unknown
CVE-2007-4097
Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.
0
Attacker Value
Unknown
CVE-2007-4096
Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
0