Show filters
43 Total Results
Displaying 41-43 of 43
Sort by:
Attacker Value
Unknown

CVE-2006-3418

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.
0
Attacker Value
Unknown

CVE-2006-0414

Disclosure Date: January 25, 2006 (last updated February 22, 2025)
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
0
Attacker Value
Unknown

CVE-2005-2643

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.
0