CVE-2006-3414

CVSS 5.0 - MEDIUM
Description

Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.

Affected Products
50 of 68
Vendor Product Version
tor tor 0.0.2
tor tor 0.0.2_pre13
tor tor 0.0.2_pre14
tor tor 0.0.2_pre15
tor tor 0.0.2_pre16
tor tor 0.0.2_pre17
tor tor 0.0.2_pre18
tor tor 0.0.2_pre19
tor tor 0.0.2_pre20
tor tor 0.0.2_pre21
tor tor 0.0.2_pre22
tor tor 0.0.2_pre23
tor tor 0.0.2_pre24
tor tor 0.0.2_pre25
tor tor 0.0.2_pre26
tor tor 0.0.2_pre27
tor tor 0.0.3
tor tor 0.0.4
tor tor 0.0.5
tor tor 0.0.6
tor tor 0.0.6.1
tor tor 0.0.6.2
tor tor 0.0.7
tor tor 0.0.7.1
tor tor 0.0.7.2
tor tor 0.0.7.3
tor tor 0.0.8
tor tor 0.0.8.1
tor tor 0.0.9
tor tor 0.0.9.1
tor tor 0.0.9.2
tor tor 0.0.9.3
tor tor 0.0.9.4
tor tor 0.0.9.5
tor tor 0.0.9.6
tor tor 0.0.9.7
tor tor 0.0.9.8
tor tor 0.0.9.9
tor tor 0.0.9.10
tor tor 0.1.0.1
tor tor 0.1.0.2
tor tor 0.1.0.3
tor tor 0.1.0.4
tor tor 0.1.0.5
tor tor 0.1.0.6
tor tor 0.1.0.7
tor tor 0.1.0.8
tor tor 0.1.0.9
tor tor 0.1.0.10
tor tor 0.1.0.11
Showing first 50 of 68 affected products.
Weakness Types
NVD-CWE-Other
CVE Information
CVE ID:
CVE-2006-3414
Published:
2006-07-07
Modified:
2026-04-16
CVSS Score:
5.0
Severity:
MEDIUM
Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected Vendors
tor
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL