CVE-2011-0427

Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

公开: 2011-01-19 最后更新: 2026-06-16 分配方: [email protected] 来源: [email protected]

结论预警: CVE-2011-0427 综合评估为中等风险(57.3/100):CVSS 技术影响为中级,利用概率偏高(EPSS 4.44%,百分位 90%) 核心证据: EPSS 显示该漏洞近期被利用的可能性处于高位。 强制指令: 被利用概率偏高—请排查暴露面并优先安排修补。

风险随态势动态变化;本站持续评估并同步更新本页展示内容。

CVE-2011-0427 的 EPSS(利用预测评分)

EPSS 日更估计相对被利用可能性;百分位表示该 CVE 在已评分漏洞中的相对排名(越高表示相对更严重)。

# 日期 旧 EPSS 分数 新 EPSS 分数 变化(新 − 旧)
1 2026-06-15 5.92% 4.44% -1.47%
2 2025-07-21 4.94% 5.92% +0.98%
3 2025-03-30 4.94%

完整 EPSS 历史 (共 10 条)

CVE-2011-0427 的 CVSS 指标

该 CVE 的 CVSS 指标。

底座分 版本 严重度 向量 可利用性 影响 分数来源
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P 点击展开
访问路径 (AV:N)
只要路由可达,即可从远端发起利用。
访问复杂度 (AC:M)
需要若干有利条件,但不至于“千年一遇”。
认证 (AU:N)
全程无需有效身份。
机密性影响 (C:P)
机密性受到部分损害。
完整性影响 (I:P)
完整性受到部分损害。
可用性影响 (A:P)
可用性受到部分损害。
8.6 6.4 [email protected]

CVE-2011-0427 的弱点枚举

CVE-2011-0427 的 OS 跟踪

vendor priority summary link
debian not yet assigned CVE-2011-0427 not yet assigned priority: Debian including 1 source packages (tor), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2011-0427
gentoo high CVE-2011-0427: 1 GLSA(s) (201110-13), 1 atom(s) (net-misc/tor); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2011-0427
ubuntu medium CVE-2011-0427 medium priority: Ubuntu including 1 source packages (tor), 8 status rows across 8 suites (dapper, hardy, karmic, lucid, maverick, natty, oneiric, upstream): DNE 3, ignored 2, not-affected 2, released 1. https://ubuntu.com/security/CVE-2011-0427

CVE-2011-0427 的影响软件 / 配置

厂商 产品 版本 原始 CPE
tor tor <= 0.2.1.28 cpe:2.3:a:tor:tor:*:*:*:*:*:*:*:*
tor tor 0.0.2 cpe:2.3:a:tor:tor:0.0.2:*:*:*:*:*:*:*
tor tor 0.0.2_pre13 cpe:2.3:a:tor:tor:0.0.2_pre13:*:*:*:*:*:*:*
tor tor 0.0.2_pre14 cpe:2.3:a:tor:tor:0.0.2_pre14:*:*:*:*:*:*:*
tor tor 0.0.2_pre15 cpe:2.3:a:tor:tor:0.0.2_pre15:*:*:*:*:*:*:*
tor tor 0.0.2_pre16 cpe:2.3:a:tor:tor:0.0.2_pre16:*:*:*:*:*:*:*
tor tor 0.0.2_pre17 cpe:2.3:a:tor:tor:0.0.2_pre17:*:*:*:*:*:*:*
tor tor 0.0.2_pre18 cpe:2.3:a:tor:tor:0.0.2_pre18:*:*:*:*:*:*:*
tor tor 0.0.2_pre19 cpe:2.3:a:tor:tor:0.0.2_pre19:*:*:*:*:*:*:*
tor tor 0.0.2_pre20 cpe:2.3:a:tor:tor:0.0.2_pre20:*:*:*:*:*:*:*
tor tor 0.0.2_pre21 cpe:2.3:a:tor:tor:0.0.2_pre21:*:*:*:*:*:*:*
tor tor 0.0.2_pre22 cpe:2.3:a:tor:tor:0.0.2_pre22:*:*:*:*:*:*:*
tor tor 0.0.2_pre23 cpe:2.3:a:tor:tor:0.0.2_pre23:*:*:*:*:*:*:*
tor tor 0.0.2_pre24 cpe:2.3:a:tor:tor:0.0.2_pre24:*:*:*:*:*:*:*
tor tor 0.0.2_pre25 cpe:2.3:a:tor:tor:0.0.2_pre25:*:*:*:*:*:*:*
tor tor 0.0.2_pre26 cpe:2.3:a:tor:tor:0.0.2_pre26:*:*:*:*:*:*:*
tor tor 0.0.2_pre27 cpe:2.3:a:tor:tor:0.0.2_pre27:*:*:*:*:*:*:*
tor tor 0.0.3 cpe:2.3:a:tor:tor:0.0.3:*:*:*:*:*:*:*
tor tor 0.0.4 cpe:2.3:a:tor:tor:0.0.4:*:*:*:*:*:*:*
tor tor 0.0.5 cpe:2.3:a:tor:tor:0.0.5:*:*:*:*:*:*:*
tor tor 0.0.6 cpe:2.3:a:tor:tor:0.0.6:*:*:*:*:*:*:*
tor tor 0.0.6.1 cpe:2.3:a:tor:tor:0.0.6.1:*:*:*:*:*:*:*
tor tor 0.0.6.2 cpe:2.3:a:tor:tor:0.0.6.2:*:*:*:*:*:*:*
tor tor 0.0.7 cpe:2.3:a:tor:tor:0.0.7:*:*:*:*:*:*:*
tor tor 0.0.7.1 cpe:2.3:a:tor:tor:0.0.7.1:*:*:*:*:*:*:*
tor tor 0.0.7.2 cpe:2.3:a:tor:tor:0.0.7.2:*:*:*:*:*:*:*
tor tor 0.0.7.3 cpe:2.3:a:tor:tor:0.0.7.3:*:*:*:*:*:*:*
tor tor 0.0.8 cpe:2.3:a:tor:tor:0.0.8:*:*:*:*:*:*:*
tor tor 0.0.8.1 cpe:2.3:a:tor:tor:0.0.8.1:*:*:*:*:*:*:*
tor tor 0.0.9 cpe:2.3:a:tor:tor:0.0.9:*:*:*:*:*:*:*
tor tor 0.0.9.1 cpe:2.3:a:tor:tor:0.0.9.1:*:*:*:*:*:*:*
tor tor 0.0.9.2 cpe:2.3:a:tor:tor:0.0.9.2:*:*:*:*:*:*:*
tor tor 0.0.9.3 cpe:2.3:a:tor:tor:0.0.9.3:*:*:*:*:*:*:*
tor tor 0.0.9.4 cpe:2.3:a:tor:tor:0.0.9.4:*:*:*:*:*:*:*
tor tor 0.0.9.5 cpe:2.3:a:tor:tor:0.0.9.5:*:*:*:*:*:*:*
tor tor 0.0.9.6 cpe:2.3:a:tor:tor:0.0.9.6:*:*:*:*:*:*:*
tor tor 0.0.9.7 cpe:2.3:a:tor:tor:0.0.9.7:*:*:*:*:*:*:*
tor tor 0.0.9.8 cpe:2.3:a:tor:tor:0.0.9.8:*:*:*:*:*:*:*
tor tor 0.0.9.9 cpe:2.3:a:tor:tor:0.0.9.9:*:*:*:*:*:*:*
tor tor 0.0.9.10 cpe:2.3:a:tor:tor:0.0.9.10:*:*:*:*:*:*:*
tor tor 0.1.0.1 cpe:2.3:a:tor:tor:0.1.0.1:*:*:*:*:*:*:*
tor tor 0.1.0.2 cpe:2.3:a:tor:tor:0.1.0.2:*:*:*:*:*:*:*
tor tor 0.1.0.3 cpe:2.3:a:tor:tor:0.1.0.3:*:*:*:*:*:*:*
tor tor 0.1.0.4 cpe:2.3:a:tor:tor:0.1.0.4:*:*:*:*:*:*:*
tor tor 0.1.0.5 cpe:2.3:a:tor:tor:0.1.0.5:*:*:*:*:*:*:*
tor tor 0.1.0.6 cpe:2.3:a:tor:tor:0.1.0.6:*:*:*:*:*:*:*
tor tor 0.1.0.7 cpe:2.3:a:tor:tor:0.1.0.7:*:*:*:*:*:*:*
tor tor 0.1.0.8 cpe:2.3:a:tor:tor:0.1.0.8:*:*:*:*:*:*:*
tor tor 0.1.0.9 cpe:2.3:a:tor:tor:0.1.0.9:*:*:*:*:*:*:*
tor tor 0.1.0.10 cpe:2.3:a:tor:tor:0.1.0.10:*:*:*:*:*:*:*
tor tor 0.1.0.11 cpe:2.3:a:tor:tor:0.1.0.11:*:*:*:*:*:*:*
tor tor 0.1.0.12 cpe:2.3:a:tor:tor:0.1.0.12:*:*:*:*:*:*:*
tor tor 0.1.0.13 cpe:2.3:a:tor:tor:0.1.0.13:*:*:*:*:*:*:*
tor tor 0.1.0.14 cpe:2.3:a:tor:tor:0.1.0.14:*:*:*:*:*:*:*
tor tor 0.1.0.15 cpe:2.3:a:tor:tor:0.1.0.15:*:*:*:*:*:*:*
tor tor 0.1.0.16 cpe:2.3:a:tor:tor:0.1.0.16:*:*:*:*:*:*:*
tor tor 0.1.0.17 cpe:2.3:a:tor:tor:0.1.0.17:*:*:*:*:*:*:*
tor tor 0.1.1 cpe:2.3:a:tor:tor:0.1.1:*:*:*:*:*:*:*
tor tor 0.1.1.1 cpe:2.3:a:tor:tor:0.1.1.1:*:*:*:*:*:*:*
tor tor 0.1.1.1 cpe:2.3:a:tor:tor:0.1.1.1:alpha:*:*:*:*:*:*
tor tor 0.1.1.2 cpe:2.3:a:tor:tor:0.1.1.2:*:*:*:*:*:*:*
tor tor 0.1.1.2 cpe:2.3:a:tor:tor:0.1.1.2:alpha:*:*:*:*:*:*
tor tor 0.1.1.3 cpe:2.3:a:tor:tor:0.1.1.3:*:*:*:*:*:*:*
tor tor 0.1.1.3 cpe:2.3:a:tor:tor:0.1.1.3:alpha:*:*:*:*:*:*
tor tor 0.1.1.4 cpe:2.3:a:tor:tor:0.1.1.4:*:*:*:*:*:*:*
tor tor 0.1.1.4 cpe:2.3:a:tor:tor:0.1.1.4:alpha:*:*:*:*:*:*
tor tor 0.1.1.5 cpe:2.3:a:tor:tor:0.1.1.5:*:*:*:*:*:*:*
tor tor 0.1.1.5 cpe:2.3:a:tor:tor:0.1.1.5:alpha:*:*:*:*:*:*
tor tor 0.1.1.6 cpe:2.3:a:tor:tor:0.1.1.6:*:*:*:*:*:*:*
tor tor 0.1.1.6 cpe:2.3:a:tor:tor:0.1.1.6:alpha:*:*:*:*:*:*
tor tor 0.1.1.7 cpe:2.3:a:tor:tor:0.1.1.7:*:*:*:*:*:*:*
tor tor 0.1.1.7 cpe:2.3:a:tor:tor:0.1.1.7:alpha:*:*:*:*:*:*
tor tor 0.1.1.8 cpe:2.3:a:tor:tor:0.1.1.8:*:*:*:*:*:*:*
tor tor 0.1.1.8 cpe:2.3:a:tor:tor:0.1.1.8:alpha:*:*:*:*:*:*
tor tor 0.1.1.9 cpe:2.3:a:tor:tor:0.1.1.9:*:*:*:*:*:*:*
tor tor 0.1.1.9 cpe:2.3:a:tor:tor:0.1.1.9:alpha:*:*:*:*:*:*
tor tor 0.1.1.10 cpe:2.3:a:tor:tor:0.1.1.10:*:*:*:*:*:*:*
tor tor 0.1.1.10 cpe:2.3:a:tor:tor:0.1.1.10:alpha:*:*:*:*:*:*
tor tor 0.1.1.11 cpe:2.3:a:tor:tor:0.1.1.11:*:*:*:*:*:*:*
tor tor 0.1.1.12 cpe:2.3:a:tor:tor:0.1.1.12:*:*:*:*:*:*:*

CVE-2011-0427 的参考链接

cvelogic Threat Intelligence