Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-3415

EPSS 0.48% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-3415

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tor 未明中间人(MITM)攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tor 0.1.1.20之前版本使用不正确的逻辑验证"OR"目的地。远程攻击者借助未明向量进行中间人(MITM)攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-3415

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-3415

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-07-07 · 29 CVEs total

CVE-2006-3417Tor client is_fast或is_stable标记节点漏洞
CVE-2006-3430PatchLink Update 'Checkprofile.ASP' SQL注入漏洞
CVE-2006-3429TTCalc Script Loan And Mortgage 跨站脚本攻击(XSS) 漏洞
CVE-2006-3428TTCalc Script Loan And Mortgage跨站脚本攻击(XSS) 漏洞
CVE-2006-3427Microsoft IE StructuredGraphicsControl远程拒绝服务漏洞
CVE-2006-3426PatchLink Update Server目录遍历漏洞
CVE-2006-3425PatchLink Update Server 'Proxyreg.ASP'认证绕过漏洞
CVE-2006-3424WebEx Downloader ActiveX控件 多个缓冲区溢出漏洞
CVE-2006-3423WebEx Downloader插件GpcUrlRoot和GpcIniFileName ActiveX/Java控件远程代码执行漏洞
CVE-2006-3422WonderEdit Pro 'User_Bottom.PHP'远程文件包含漏洞
CVE-2006-3421SmartSiteCMS多个远程文件包含漏洞
CVE-2006-3420MyBulletinBoard 'editpost.php '跨站请求伪造(CSRF) 漏洞
CVE-2006-3419Tor before OpenSSL伪随机暴力破解漏洞
CVE-2006-3418Tor 验证服务器伪造权限漏洞
CVE-2006-3458Zope Docutils模块信息泄露漏洞
CVE-2006-3416Tor 中继命令网路解散漏洞
CVE-2006-3414Tor before 非IP地址的服务器描述符漏洞
CVE-2006-3413Tor "logfile"记录敏感的信息信息泄露漏洞
CVE-2006-3412Tor before dir服务器、直接连接或代理服务器安全绕过漏洞
CVE-2006-3411Tor TLS握手根据TLS公/私钥加密密钥的强力攻击漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-3415

No comments yet


Leave a comment