Debian Tor vulnerabilities
95 known vulnerabilities affecting debian/tor.
Total CVEs
95
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM42LOW23
Vulnerabilities
Page 1 of 5
CVE-2025-4444MEDIUMCVSS 6.3fixed in tor 0.4.9.6-0+deb12u1 (bookworm)2025
CVE-2025-4444 [MEDIUM] CVE-2025-4444: tor - A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is ...
A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered difficult. Upgrading to version 0.4.8.18 and 0.4.9.
debian
CVE-2023-23589MEDIUMCVSS 6.5fixed in tor 0.4.7.13-1 (bookworm)2023
CVE-2023-23589 [MEDIUM] CVE-2023-23589: tor - The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsaf...
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
Scope: local
bookworm: resolved (fixed in 0.4.7.13-1)
bullseye: resolved (fixed in 0.4.5.16-1)
forky: resolved (fixed in 0.4.7.13-1)
sid: resolved (fixed in 0.4.7.13-1)
trixie: resolved (fixed in 0.4.7.13-
debian
CVE-2022-33903HIGHCVSS 7.5fixed in tor 0.4.7.8-1 (bookworm)2022
CVE-2022-33903 [HIGH] CVE-2022-33903: tor - Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT est...
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
Scope: local
bookworm: resolved (fixed in 0.4.7.8-1)
bullseye: resolved
forky: resolved (fixed in 0.4.7.8-1)
sid: resolved (fixed in 0.4.7.8-1)
trixie: resolved (fixed in 0.4.7.8-1)
debian
CVE-2021-34548HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34548 [HIGH] CVE-2021-34548: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker c...
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.
Scope: local
bookworm: resolved (fixed in 0.4.5.9-1)
bullseye: resolved (fixed in 0.4.5.9-1)
forky: resolved (fixed in 0.4.5.9-1)
sid: resolved (fixed in 0.4.5.9-1)
trixie: resolved (fixed in 0.4.
debian
CVE-2021-34550HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34550 [HIGH] CVE-2021-34550: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion ...
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor
Scope: local
bookworm: resolved (fixed in 0.4.5.9-1)
bullseye: resolved (fixed in 0.4.5.9-1)
forky: resolved (fixed in 0.4.5.9-1)
sid: resolved (fixed in 0.4.5.9-1)
trixi
debian
CVE-2021-38385HIGHCVSS 7.5fixed in tor 0.4.5.10-1 (bookworm)2021
CVE-2021-38385 [HIGH] CVE-2021-38385: tor - Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between b...
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
Scope: local
bookworm: resolved (fixed in 0.4.5.10-1)
bullseye: resolved (fixed in 0.4.5.10-1~deb11u1)
forky: resolved (fixed in 0.4.5.10-1)
sid: resolved (fixed in 0.4.5
debian
CVE-2021-34549HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34549 [HIGH] CVE-2021-34549: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mi...
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
Scope: local
bookworm: resolved (fixed in 0.4.5.9-1)
bullseye: resolved (fixed in 0.4.5.9-1)
forky: resolved (fixed in 0.4.5.9-1)
si
debian
CVE-2021-28089HIGHCVSS 7.5fixed in tor 0.4.5.7-1 (bookworm)2021
CVE-2021-28089 [HIGH] CVE-2021-28089: tor - Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to ...
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
Scope: local
bookworm: resolved (fixed in 0.4.5.7-1)
bullseye: resolved (fixed in 0.4.5.7-1)
forky: resolved (fixed in 0.4.5.7-1)
sid: resolved (fixed in 0.4.5.7-1)
trixie: resolved (fixed in 0.4.5.7-1)
debian
CVE-2021-28090MEDIUMCVSS 5.3fixed in tor 0.4.5.7-1 (bookworm)2021
CVE-2021-28090 [MEDIUM] CVE-2021-28090: tor - Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities t...
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
Scope: local
bookworm: resolved (fixed in 0.4.5.7-1)
bullseye: resolved (fixed in 0.4.5.7-1)
forky: resolved (fixed in 0.4.5.7-1)
sid: resolved (fixed in 0.4.5.7-1)
trixie: resolved (fixed in 0.4.5.7-1)
debian
CVE-2020-10592HIGHCVSS 7.5fixed in tor 0.4.2.7-1 (bookworm)2020
CVE-2020-10592 [HIGH] CVE-2020-10592: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem...
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
Scope: local
bookworm: resolved (fixed in 0.4.2.7-1)
bullseye: resolved (fixed in 0.4.2.7-1)
forky: resolved (fixed in 0.4.2.7-1)
sid: resolved (fixed in 0.4.2.7-1)
trixie: resolved (fixed in 0.4.2.7-1)
debian
CVE-2020-10593HIGHCVSS 7.5fixed in tor 0.4.2.7-1 (bookworm)2020
CVE-2020-10593 [HIGH] CVE-2020-10593: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem...
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
Scope: local
bookworm: resolved (fixed in 0.4.2.7-1)
bullseye: resolved (fixed in 0.4.2.7-
debian
CVE-2020-15572LOWCVSS 7.5fixed in tor 0.4.3.6-1 (bookworm)2020
CVE-2020-15572 [HIGH] CVE-2020-15572: tor - Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denia...
Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.
Scope: local
bookworm: resolved (fixed in 0.4.3.6-1)
bullseye: resolved (fixed in 0.4.3.6-1)
forky: resolved (fixed in 0.4.3.6-1)
sid: resolved (fixed in 0.4.3.6-1)
tri
debian
CVE-2020-8516LOWCVSS 5.32020
CVE-2020-8516 [MEDIUM] CVE-2020-8516: tor - The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify th...
The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability
Scope: local
bookworm: open
bullseye: open
forky: open
debian
CVE-2019-8955HIGHCVSS 7.5fixed in tor 0.3.5.8-1 (bookworm)2019
CVE-2019-8955 [HIGH] CVE-2019-8955: tor - In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4...
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
Scope: local
bookworm: resolved (fixed in 0.3.5.8-1)
bullseye: resolved (fixed in 0.3.5.8-1)
forky: resolved (fixed in 0.3.5.8-1)
sid: resolved (fixed in
debian
CVE-2018-0491HIGHCVSS 7.5PoCfixed in tor 0.3.2.10-1 (bookworm)2018
CVE-2018-0491 [HIGH] CVE-2018-0491: tor - A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows ...
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.
Scope: local
bookworm: resolved (fixed in 0.3.2.10-1)
bullseye: resolved (fixed in 0.3.2.10-1)
forky: resolved (fixed in 0.3.2.10-1)
sid:
debian
CVE-2018-0490HIGHCVSS 7.5fixed in tor 0.3.2.10-1 (bookworm)2018
CVE-2018-0490 [HIGH] CVE-2018-0490: tor - An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3...
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.
Scope: local
bookworm: reso
debian
CVE-2017-11565HIGHCVSS 7.5v0.2.9.11-12017-07-23
CVE-2017-11565 [HIGH] CVE-2017-11565: debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec
debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leverag
nvddebian
CVE-2017-8823HIGHCVSS 8.1fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8823 [HIGH] CVE-2017-8823: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9....
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013.
Scope: local
bookworm: resolved (fixed in 0.3.1.9-1)
bullseye: resolved (fixed in
debian
CVE-2017-0376HIGHCVSS 7.5fixed in tor 0.2.9.11-1 (bookworm)2017
CVE-2017-0376 [HIGH] CVE-2017-0376: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
Scope: local
bookworm: resolved (fixed in 0.2.9.11-1)
bullseye: resolved (fixed in 0.2.9.11-1)
forky: resolved (fixed in 0.2.9.11-1)
sid: resolved (fixed in 0.2.9.11
debian
CVE-2017-8821HIGHCVSS 7.5fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8821 [HIGH] CVE-2017-8821: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9....
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011.
Scope
debian
1 / 5Next →