Torproject Tor vulnerabilities
100 known vulnerabilities affecting torproject/tor.
Total CVEs
100
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH31MEDIUM61LOW2
Vulnerabilities
Page 3 of 5
CVE-2021-28090P4MEDIUMCVSS 5.3fixed in 0.3.5.14≥ 0.4.4.4, < 0.4.4.8+5 more2021-03-19
CVE-2021-28090 [MEDIUM] CWE-617 CVE-2021-28090: Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an asser
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
nvdosv
CVE-2023-23589P4MEDIUMCVSS 6.5fixed in 0.4.7.132023-01-14
CVE-2023-23589 [MEDIUM] CWE-693 CVE-2023-23589: The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol ca
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
nvdosv
CVE-2014-5117P4MEDIUMCVSS 5.8≤ 0.2.4.22v0.0.2+107 more2014-07-30
CVE-2014-5117 [MEDIUM] CVE-2014-5117: Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY
Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of communicating information about hidden service names.
nvdosv
CVE-2017-0380P4MEDIUMCVSS 5.9≤ 0.2.8.14v0.2.9.0+28 more2017-09-18
CVE-2017-0380 [MEDIUM] CWE-532 CVE-2017-0380: The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x befo
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitializ
nvdosv
CVE-2026-44599P4MEDIUMCVSS 5.3fixed in 0.4.9.72026-05-07
CVE-2026-44599 [MEDIUM] CWE-669 CVE-2026-44599: Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
nvd
CVE-2020-8516P4MEDIUMCVSS 5.3≤ 0.4.1.8≥ 0.4.2.0, ≤ 0.4.2.62020-02-02
CVE-2020-8516 [MEDIUM] CVE-2020-8516: The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node
The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability
nvd
CVE-2006-3417P4MEDIUMCVSS 6.4≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3417 [MEDIUM] CVE-2006-3417: Tor client before 0
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard" (is_guard) systems by directory authorities.
osv
CVE-2007-4098P4MEDIUMCVSS 5.8≥ 0, < 0.1.2.15-12007-07-30
CVE-2007-4098 [MEDIUM] CVE-2007-4098: Tor before 0
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.
osv
CVE-2026-44600P4MEDIUMCVSS 5.3fixed in 0.4.9.72026-05-07
CVE-2026-44600 [MEDIUM] CWE-696 CVE-2026-44600: Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
nvd
CVE-2008-5397P4HIGHCVSS 7.2≥ 0, < 0.2.0.32-12008-12-09
CVE-2008-5397 [HIGH] CVE-2008-5397: Tor before 0
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
osv
CVE-2006-3407P4MEDIUMCVSS 6.4≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3407 [MEDIUM] CVE-2006-3407: Tor before 0
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
osv
CVE-2011-0015P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0015 [MEDIUM] CVE-2011-0015: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.
osv
CVE-2006-3415P4MEDIUMCVSS 6.4≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3415 [MEDIUM] CVE-2006-3415: Tor before 0
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
osv
CVE-2011-2768P4MEDIUMCVSS 5.8≥ 0, < 0.2.2.34-12011-12-23
CVE-2011-2768 [MEDIUM] CVE-2011-2768: Tor before 0
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.
osv
CVE-2012-5573P4MEDIUMCVSS 5.0≤ 0.2.3.24v0.0.2+82 more2013-01-01
CVE-2012-5573 [MEDIUM] CWE-399 CVE-2012-5573: The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circu
The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.
nvdosv
CVE-2005-2050P4MEDIUMCVSS 5.0≥ 0, < 0.0.9.10-12005-06-28
CVE-2005-2050 [MEDIUM] CVE-2005-2050: Unknown vulnerability in Tor before 0
Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.
osv
CVE-2021-46702P4MEDIUMCVSS 5.5v9.0.72022-02-26
CVE-2021-46702 [MEDIUM] CWE-404 CVE-2021-46702: Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allo
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occ
nvd
CVE-2007-4096P4MEDIUMCVSS 5.8≥ 0, < 0.1.2.15-12007-07-30
CVE-2007-4096 [MEDIUM] CVE-2007-4096: Buffer overflow in Tor before 0
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
osv
CVE-2011-1924P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.30-12011-06-14
CVE-2011-1924 [MEDIUM] CVE-2011-1924: Buffer overflow in the policy_summarize function in or/policies
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
osv
CVE-2012-3518P4MEDIUMCVSS 5.0≥ 0, < 0.2.3.20-rc-12012-08-26
CVE-2012-3518 [MEDIUM] CVE-2012-3518: The networkstatus_parse_vote_from_string function in routerparse
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.
osv