Search: "tor"

431 CVEs found

The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.

Published: 2000-05-11
Products: 1
Vendors:
microsoft
CVE-2004-1212
5.0 MEDIUM

Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.

Published: 2005-01-10
Products: 1
Vendors:
blog_torrent
CVE-2005-2050
5.0 MEDIUM

Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.

Published: 2005-06-28
Products: 10
Vendors:
tor

Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain s...

Published: 2005-07-12
Products: 1
Vendors:
blog_torrent
CVE-2005-2643
5.0 MEDIUM

Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers...

Published: 2005-08-23
Products: 27
Vendors:
tor
CVE-2005-4160
5.0 MEDIUM

Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.

Published: 2005-12-11
Products: 1
Vendors:
torrential
CVE-2005-4253
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.

Published: 2005-12-15
Products: 1
Vendors:
torrential

Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.

Published: 2006-01-21
Products: 1
Vendors:
bitcomet
CVE-2006-0414
5.0 MEDIUM

Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to ...

Published: 2006-01-25
Products: 57
Vendors:
tor
CVE-2006-3407
6.4 MEDIUM

Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3408
5.0 MEDIUM

Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.

Published: 2006-07-07
Products: 68
Vendors:
tor

Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3410
5.0 MEDIUM

Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3411
6.4 MEDIUM

TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the enc...

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3412
6.4 MEDIUM

Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3413
5.0 MEDIUM

The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3414
5.0 MEDIUM

Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3415
6.4 MEDIUM

Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3416
5.0 MEDIUM

Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section...

Published: 2006-07-07
Products: 68
Vendors:
tor
CVE-2006-3417
6.4 MEDIUM

Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard"...

Published: 2006-07-07
Products: 68
Vendors:
tor