Debian Tor vulnerabilities
89 known vulnerabilities affecting debian/tor.
Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM42LOW17
Vulnerabilities
Page 5 of 5
CVE-2011-4896P4LOWCVSS 4.3fixed in tor 0.2.2.27-beta-1 (bookworm)2011
CVE-2011-4896 [MEDIUM] CVE-2011-4896: tor - Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previousl...
Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.
Scope: local
bookworm: resolved (fixed in 0.2.2.27-beta-1)
bullseye: resolved (fixed
debian
CVE-2009-0938P4MEDIUMCVSS 5.0fixed in tor 0.2.0.34-1 (bookworm)2009
CVE-2009-0938 [MEDIUM] CVE-2009-0938: tor - Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cau...
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."
Scope: local
bookworm: resolved (fixed in 0.2.0.34-1)
bullseye: resolved (fixed in 0.2.0.34-1)
forky: resolved (fixed in 0.2.0.34-1)
sid: resolved (fixed in 0.2.0.34-1)
trixie: resolved (fixed in 0.2.0.34-1)
debian
CVE-2009-0936P4MEDIUMCVSS 5.0fixed in tor 0.2.0.34-1 (bookworm)2009
CVE-2009-0936 [MEDIUM] CVE-2009-0936: tor - Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a den...
Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."
Scope: local
bookworm: resolved (fixed in 0.2.0.34-1)
bullseye: resolved (fixed in 0.2.0.34-1)
forky: resolved (fixed in 0.2.0.34-1)
sid: resolved (fixed in 0.2.0.34-1)
trixie: resolved (fixed in 0.2.0.34-1)
debian
CVE-2025-4444P4MEDIUMCVSS 6.3fixed in tor 0.4.9.6-0+deb12u1 (bookworm)2025
CVE-2025-4444 [MEDIUM] CVE-2025-4444: tor - A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is ...
A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered difficult. Upgrading to version 0.4.8.18 and 0.4.9.
debian
CVE-2009-2425P4LOWCVSS 5.0fixed in tor 0.2.0.35-1 (bookworm)2009
CVE-2009-2425 [MEDIUM] CVE-2009-2425: tor - Tor before 0.2.0.35 allows remote attackers to cause a denial of service (applic...
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
Scope: local
bookworm: resolved (fixed in 0.2.0.35-1)
bullseye: resolved (fixed in 0.2.0.35-1)
forky: resolved (fixed in 0.2.0.35-1)
sid: resolved (fixed in 0.2.0.35-1)
trixie: resolved (fixed in 0.2.0.35-1)
debian
CVE-2006-3419P4MEDIUMCVSS 5.0fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3419 [MEDIUM] CVE-2006-3419: tor - Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead...
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
debian
CVE-2011-4897P4LOWCVSS 4.3fixed in tor 0.2.2.27-beta-1 (bookworm)2011
CVE-2011-4897 [MEDIUM] CVE-2011-4897: tor - Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname confi...
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.
Scope: local
bookworm: resolved (fixed in 0.2.2.27-beta-1)
bullseye: resolved (fixed in 0.2.2.27-beta-1)
forky: resolved (fixed in
debian
CVE-2017-8822P4LOWCVSS 3.7fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8822 [LOW] CVE-2017-8822: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9....
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
Scope: local
bookworm: resolved (fixed in 0.3.1.9-1)
bullseye: resolved (fixed in 0.3.1.9
debian
CVE-2011-0016P4LOWCVSS 2.1fixed in tor 0.2.1.29-1 (bookworm)2011
CVE-2011-0016 [LOW] CVE-2011-0016: tor - Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage k...
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.
Scope: local
bookworm: resolved (fixed in 0.2.1.29-1)
bullseye: resolved (fixed in 0.2.1.29-1)
forky: resolved (fixed in 0.2
debian
← Previous5 / 5