NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47983  CVE-2009-0654  Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product"s design "accepted end-to-end correlation as an attack that is too expensive to solve."    5.1  Medium  2017-01-07  2009-02-25  View
68332  CVE-2005-2643  Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.    Medium  2017-01-03  2016-10-17  View
67441  CVE-2005-1716  TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.    Medium  2017-01-03  2008-09-05  View
74479  CVE-2003-1409  TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.    Medium  2017-01-03  2008-09-05  View
23872  CVE-2015-1608  Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.    Medium  2017-01-19  2016-12-30  View

Page 2491 of 17672, showing 5 records out of 88360 total, starting on record 12451, ending on 12455

Actions