Torproject Tor vulnerabilities
100 known vulnerabilities affecting torproject/tor.
Total CVEs
100
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH31MEDIUM61LOW2
Vulnerabilities
Page 4 of 5
CVE-2006-3414P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3414 [MEDIUM] CVE-2006-3414: Tor before 0
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
osv
CVE-2013-7295P4MEDIUMCVSS 4.0≤ 0.2.4.19v0.2.4.1+17 more2014-01-17
CVE-2013-7295 [MEDIUM] CWE-310 CVE-2013-7295: Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via u
nvdosv
CVE-2007-4099P4MEDIUMCVSS 5.8≥ 0, < 0.1.2.15-12007-07-30
CVE-2007-4099 [MEDIUM] CVE-2007-4099: Tor before 0
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks.
osv
CVE-2006-0414P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.11-alpha-12006-01-25
CVE-2006-0414 [MEDIUM] CVE-2006-0414: Tor before 0
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
osv
CVE-2012-4922P4MEDIUMCVSS 5.0≤ 0.2.2.38v0.0.2+79 more2012-09-14
CVE-2012-4922 [MEDIUM] CVE-2012-4922: The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, doe
The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.
nvdosv
CVE-2012-4419P4MEDIUMCVSS 5.0≤ 0.2.2.38v0.0.2+78 more2012-09-14
CVE-2012-4419 [MEDIUM] CVE-2012-4419: The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x be
The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison.
nvdosv
CVE-2006-3418P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3418 [MEDIUM] CVE-2006-3418: Tor before 0
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.
osv
CVE-2010-0383P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.22-12010-01-25
CVE-2010-0383 [MEDIUM] CVE-2010-0383: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
osv
CVE-2006-3411P4MEDIUMCVSS 6.4≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3411 [MEDIUM] CVE-2006-3411: TLS handshakes in Tor before 0
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
osv
CVE-2012-3517P4MEDIUMCVSS 5.0≥ 0, < 0.2.3.20-rc-12012-08-26
CVE-2012-3517 [MEDIUM] CVE-2012-3517: Use-after-free vulnerability in dns
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
osv
CVE-2010-0385P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.22-12010-01-25
CVE-2010-0385 [MEDIUM] CVE-2010-0385: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
osv
CVE-2009-2426P4MEDIUMCVSS 5.0≥ 0, < 0.2.0.35-12009-07-10
CVE-2009-2426 [MEDIUM] CVE-2009-2426: The connection_edge_process_relay_cell_not_open function in src/or/relay
The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information.
osv
CVE-2006-3410P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3410 [MEDIUM] CVE-2006-3410: Tor before 0
Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks.
osv
CVE-2012-2250P4MEDIUMCVSS 5.0≤ 0.2.3.23v0.0.2+81 more2014-02-03
CVE-2012-2250 [MEDIUM] CVE-2012-2250: Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and d
Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.
nvdosv
CVE-2011-4895P4MEDIUMCVSS 4.3≥ 0, < 0.2.2.34-12011-12-23
CVE-2011-4895 [MEDIUM] CVE-2011-4895: Tor before 0
Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.
osv
CVE-2011-4894P4MEDIUMCVSS 4.3≥ 0, < 0.2.2.34-12011-12-23
CVE-2011-4894 [MEDIUM] CVE-2011-4894: Tor before 0
Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.
osv
CVE-2007-4097P4MEDIUMCVSS 6.4≥ 0, < 0.1.2.15-12007-07-30
CVE-2007-4097 [MEDIUM] CVE-2007-4097: Tor before 0
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.
osv
CVE-2011-2769P4MEDIUMCVSS 4.3≥ 0, < 0.2.2.34-12011-12-23
CVE-2011-2769 [MEDIUM] CVE-2011-2769: Tor before 0
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
osv
CVE-2011-0491P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0491 [MEDIUM] CVE-2011-0491: The tor_realloc function in Tor before 0
The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors, related to "underflow errors."
osv
CVE-2012-3519P4MEDIUMCVSS 5.0≥ 0, < 0.2.3.20-rc-12012-08-26
CVE-2012-3519 [MEDIUM] CVE-2012-3519: routerlist
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-channel attack.
osv