Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-3419

EPSS 0.33% · P56
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-3419

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tor before OpenSSL伪随机暴力破解漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tor before 0.1.1.20 使用 OpenSSL伪随机字节(RAND_pseudo_bytes)而非强密码RAND_字节,并在以160位组块起动时播种entropy值而不重复播种,可以使攻击者更易于进行强力的猜测攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-3419

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-3419

Please Login to view more intelligence information

Same Patch Batch · n/a · 2006-07-07 · 29 CVEs total

CVE-2006-3416Tor 中继命令网路解散漏洞
CVE-2006-3430PatchLink Update 'Checkprofile.ASP' SQL注入漏洞
CVE-2006-3429TTCalc Script Loan And Mortgage 跨站脚本攻击(XSS) 漏洞
CVE-2006-3428TTCalc Script Loan And Mortgage跨站脚本攻击(XSS) 漏洞
CVE-2006-3427Microsoft IE StructuredGraphicsControl远程拒绝服务漏洞
CVE-2006-3426PatchLink Update Server目录遍历漏洞
CVE-2006-3425PatchLink Update Server 'Proxyreg.ASP'认证绕过漏洞
CVE-2006-3424WebEx Downloader ActiveX控件 多个缓冲区溢出漏洞
CVE-2006-3423WebEx Downloader插件GpcUrlRoot和GpcIniFileName ActiveX/Java控件远程代码执行漏洞
CVE-2006-3422WonderEdit Pro 'User_Bottom.PHP'远程文件包含漏洞
CVE-2006-3421SmartSiteCMS多个远程文件包含漏洞
CVE-2006-3420MyBulletinBoard 'editpost.php '跨站请求伪造(CSRF) 漏洞
CVE-2006-3418Tor 验证服务器伪造权限漏洞
CVE-2006-3417Tor client is_fast或is_stable标记节点漏洞
CVE-2006-3458Zope Docutils模块信息泄露漏洞
CVE-2006-3415Tor 未明中间人(MITM)攻击漏洞
CVE-2006-3414Tor before 非IP地址的服务器描述符漏洞
CVE-2006-3413Tor "logfile"记录敏感的信息信息泄露漏洞
CVE-2006-3412Tor before dir服务器、直接连接或代理服务器安全绕过漏洞
CVE-2006-3411Tor TLS握手根据TLS公/私钥加密密钥的强力攻击漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-3419

No comments yet


Leave a comment