Torproject Tor vulnerabilities
100 known vulnerabilities affecting torproject/tor.
Total CVEs
100
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH31MEDIUM61LOW2
Vulnerabilities
Page 5 of 5
CVE-2006-3408P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3408 [MEDIUM] CVE-2006-3408: Unspecified vulnerability in the directory server (dirserver) in Tor before 0
Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.
osv
CVE-2012-2249P4MEDIUMCVSS 5.0≤ 0.2.3.22v0.0.2+80 more2014-02-03
CVE-2012-2249 [MEDIUM] CVE-2012-2249: Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and d
Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.
nvdosv
CVE-2005-2643P4MEDIUMCVSS 5.0≥ 0, < 0.1.0.14-12005-08-23
CVE-2005-2643 [MEDIUM] CVE-2005-2643: Tor 0
Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.
osv
CVE-2006-4508P4MEDIUMCVSS 4.0≥ 0, < 0.1.1.23-12006-08-31
CVE-2006-4508 [MEDIUM] CVE-2006-4508: Unspecified vulnerability in (1) Tor 0
Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor traffic through clients or cause a denial of service (flood) via unspecified vectors.
osv
CVE-2011-0493P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0493 [MEDIUM] CVE-2011-0493: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
osv
CVE-2011-0490P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0490 [MEDIUM] CVE-2011-0490: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denial of service (daemon crash) via vectors that trigger certain log messages.
osv
CVE-2006-3416P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3416 [MEDIUM] CVE-2006-3416: Tor before 0
Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section of the developer changelog, the developer clarified on 20060707 that this is only a self-DoS. Therefore this issue should not be included in CVE
osv
CVE-2009-0937P4MEDIUMCVSS 5.0≥ 0, < 0.2.0.34-12009-03-18
CVE-2009-0937 [MEDIUM] CVE-2009-0937: Unspecified vulnerability in Tor before 0
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors.
osv
CVE-2011-0492P4MEDIUMCVSS 5.0≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0492 [MEDIUM] CVE-2011-0492: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that trigger a certain file size, as demonstrated by the cached-descriptors.new file.
osv
CVE-2006-3413P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3413 [MEDIUM] CVE-2006-3413: The privoxy configuration file in Tor before 0
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.
osv
CVE-2007-3165P4MEDIUMCVSS 5.0≥ 0, < 0.1.2.14-12007-06-11
CVE-2007-3165 [MEDIUM] CVE-2007-3165: Tor before 0
Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.
osv
CVE-2011-4896P4MEDIUMCVSS 4.3≥ 0, < 0.2.2.27-beta-12011-12-23
CVE-2011-4896 [MEDIUM] CVE-2011-4896: Tor before 0
Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.
osv
CVE-2009-0938P4MEDIUMCVSS 5.0≥ 0, < 0.2.0.34-12009-03-18
CVE-2009-0938 [MEDIUM] CVE-2009-0938: Unspecified vulnerability in Tor before 0
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."
osv
CVE-2009-0936P4MEDIUMCVSS 5.0≥ 0, < 0.2.0.34-12009-03-18
CVE-2009-0936 [MEDIUM] CVE-2009-0936: Unspecified vulnerability in Tor before 0
Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."
osv
CVE-2025-4444P4MEDIUMCVSS 6.3≥ 0, < 0.4.9.6-0+deb12u1≥ 0, < 0.4.9.6-0+deb13u1+1 more2025-09-18
CVE-2025-4444 [MEDIUM] CVE-2025-4444: A security flaw has been discovered in Tor up to 0
A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered difficult. Upgrading to version 0.4.8.18 and 0.4.9.3-alpha is recommended to address this
osv
CVE-2009-2425P4MEDIUMCVSS 5.0≥ 0, < 0.2.0.35-12009-07-10
CVE-2009-2425 [MEDIUM] CVE-2009-2425: Tor before 0
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
osv
CVE-2006-3419P4MEDIUMCVSS 5.0≥ 0, < 0.1.1.20-12006-07-07
CVE-2006-3419 [MEDIUM] CVE-2006-3419: Tor before 0
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
osv
CVE-2011-4897P4MEDIUMCVSS 4.3≥ 0, < 0.2.2.27-beta-12011-12-23
CVE-2011-4897 [MEDIUM] CVE-2011-4897: Tor before 0
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.
osv
CVE-2017-8822P4LOWCVSS 3.7≥ 0, < 0.3.1.9-12017-12-03
CVE-2017-8822 [LOW] CVE-2017-8822: In Tor before 0
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
osv
CVE-2011-0016P4LOWCVSS 2.1≥ 0, < 0.2.1.29-12011-01-19
CVE-2011-0016 [LOW] CVE-2011-0016: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.
osv
← Previous5 / 5