Show filters
44 Total Results
Displaying 41-44 of 44
Sort by:
Attacker Value
Unknown

CVE-2006-3418

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.
0
Attacker Value
Unknown

CVE-2006-0414

Disclosure Date: January 25, 2006 (last updated February 22, 2025)
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
0
Attacker Value
Unknown

CVE-2005-2643

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.
0
Attacker Value
Unknown

CVE-2005-2050

Disclosure Date: June 28, 2005 (last updated February 22, 2025)
Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.
0