cbcvebase.
CVE-2007-4098
published 2007-07-30

CVE-2007-4098: Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject…

PriorityP426medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.90%
77.3th percentile
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiantor< tor 0.1.2.15-1 (bookworm)tor 0.1.2.15-1 (bookworm)
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.