CVE-2007-1103
Last modified
CVE-2007-1103 is a vulnerability of currently unknown severity. Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.. EPSS estimates a 1.70% chance of exploitation in the next 30 days.
Description
Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tor | Tor | <= 0.1.1.26 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1103?
How severe is CVE-2007-1103?
How do I fix CVE-2007-1103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1097Unrestricted file upload vulnerability in the onAttachFiles …
- CVE-2007-1098Multiple unspecified vulnerabilities in ScryMUD before 2.1.1…
- CVE-2007-1099dbclient in Dropbear SSH client before 0.49 does not suffici…
- CVE-2007-1100Directory traversal vulnerability in download.php in Ahmet S…
- CVE-2007-1101Multiple cross-site scripting (XSS) vulnerabilities in Photo…
- CVE-2007-1102Photostand 1.2.0 allows remote attackers to obtain sensitive…
- CVE-2007-1104PHP remote file inclusion vulnerability in top.php in PHP Mo…
- CVE-2007-1105PHP remote file inclusion vulnerability in functions.php in …
- CVE-2007-1106PHP remote file inclusion vulnerability in includes/function…
- CVE-2007-1107SQL injection vulnerability in thumbnails.php in Coppermine …
- CVE-2007-1108PHP remote file inclusion vulnerability in index.php in Chri…
- CVE-2007-1109Multiple cross-site scripting (XSS) vulnerabilities in Phpwe…
Are you affected by CVE-2007-1103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
