cbcvebase.

Torproject Tor vulnerabilities

100 known vulnerabilities affecting torproject/tor.

Total CVEs
100
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH31MEDIUM61LOW2

Vulnerabilities

Page 2 of 5
CVE-2019-8955P3HIGHCVSS 7.5fixed in 0.3.3.12≥ 0.3.4.8, < 0.3.4.11+17 more2019-02-21
CVE-2019-8955 [HIGH] CWE-770 CVE-2019-8955: In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-al In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
nvdosv
CVE-2020-10592P3HIGHCVSS 7.5≥ 0.3.5, < 0.3.5.10fixed in 0.4.1.9+1 more2020-03-23
CVE-2020-10592 [HIGH] CVE-2020-10592: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
nvdosv
CVE-2015-2688P3HIGHCVSS 7.5fixed in 0.2.4.26≥ 0.2.5.1, < 0.2.5.112020-01-24
CVE-2015-2688 [HIGH] CWE-755 CVE-2015-2688: buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected ar buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
nvdosv
CVE-2017-8821P3HIGHCVSS 7.5≥ 0, < 0.3.1.9-12017-12-03
CVE-2017-8821 [HIGH] CVE-2017-8821: In Tor before 0 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011.
osv
CVE-2009-0414P4CRITICALCVSS 10.0≥ 0, < 0.2.0.33-12009-02-03
CVE-2009-0414 [CRITICAL] CVE-2009-0414: Unspecified vulnerability in Tor before 0 Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
osv
CVE-2016-1254P3HIGHCVSS 7.5fixed in 0.2.8.122017-12-05
CVE-2016-1254 [HIGH] CWE-119 CVE-2016-1254: Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a c Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
nvdosv
CVE-2020-10593P3HIGHCVSS 7.5≥ 0.3.5, < 0.3.5.10fixed in 0.4.1.9+1 more2020-03-23
CVE-2020-10593 [HIGH] CWE-401 CVE-2020-10593: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
nvdosv
CVE-2017-8819P3HIGHCVSS 7.5≥ 0, < 0.3.1.9-12017-12-03
CVE-2017-8819 [HIGH] CVE-2017-8819: In Tor before 0 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
osv
CVE-2006-3409P3HIGHCVSS 7.5≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3409 [HIGH] CVE-2006-3409: Integer overflow in Tor before 0 Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.
osv
CVE-2018-0490P4HIGHCVSS 7.5≤ 0.2.9.14≥ 0.3.1.7, ≤ 0.3.1.9+16 more2018-03-05
CVE-2018-0490 [HIGH] CWE-476 CVE-2018-0490: An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10 An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.
nvdosv
CVE-2015-2928P4HIGHCVSS 7.5fixed in 0.2.4.27≥ 0.2.5.1, < 0.2.5.12+1 more2020-01-24
CVE-2015-2928 [HIGH] CVE-2015-2928: The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0 The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
nvdosv
CVE-2011-0427P4MEDIUMCVSS 6.8≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0427 [MEDIUM] CVE-2011-0427: Heap-based buffer overflow in Tor before 0 Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
osv
CVE-2017-0375P4HIGHCVSS 7.5fixed in 0.3.0.82017-06-09
CVE-2017-0375 [HIGH] CWE-617 CVE-2017-0375: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and d The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
nvd
CVE-2017-0376P4HIGHCVSS 7.5fixed in 0.3.0.82017-06-09
CVE-2017-0376 [HIGH] CWE-617 CVE-2017-0376: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and d The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
nvdosv
CVE-2017-16541P3MEDIUMCVSS 6.5fixed in 7.0.92017-11-04
CVE-2017-16541 [MEDIUM] CWE-200 CVE-2017-16541: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
nvd
CVE-2017-8820P4HIGHCVSS 7.5≥ 0, < 0.3.1.9-12017-12-03
CVE-2017-8820 [HIGH] CVE-2017-8820: In Tor before 0 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.
osv
CVE-2022-33903P4HIGHCVSS 7.5≥ 0.4.7.1, < 0.4.7.82022-07-17
CVE-2022-33903 [HIGH] CVE-2022-33903: Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation. Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
nvdosv
CVE-2006-3412P4MEDIUMCVSS 6.4≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3412 [MEDIUM] CVE-2006-3412: Tor before 0 Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.
osv
CVE-2015-2929P4HIGHCVSS 7.5fixed in 0.2.4.27≥ 0.2.5.1, < 0.2.5.12+1 more2020-01-24
CVE-2015-2929 [HIGH] CVE-2015-2929: The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0 The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
nvdosv
CVE-2009-0939P4CRITICALCVSS 10.0≥ 0, < 0.2.0.34-12009-03-18
CVE-2009-0939 [CRITICAL] CVE-2009-0939: Tor before 0 Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
osv
Torproject Tor vulnerabilities | cvebase