Skip to main content

Vendor/product archive

torproject / tor CVEs

Beta · best-effort

41 CVEs tagged to torproject / tor0 Critical, 22 High, 13 Medium, 6 Low, 0 Unrated.

CVE-2026-44603

Published May 7, 2026

Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44602

Published May 7, 2026

Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44601

Published May 7, 2026

Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44600

Published May 7, 2026

Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44599

Published May 7, 2026

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44597

Published May 7, 2026

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2022-33903

Published Jul 17, 2022

Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46702

Published Feb 26, 2022

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain informati…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38385

Published Aug 30, 2021

Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failur…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34550

Published Jun 29, 2021

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34549

Published Jun 29, 2021

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34548

Published Jun 29, 2021

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15572

Published Jul 15, 2020

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (N…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8516

Published Feb 2, 2020

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2929

Published Jan 24, 2020

The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (asser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2928

Published Jan 24, 2020

The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (ass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2689

Published Jan 24, 2020

Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2688

Published Jan 24, 2020

buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8955

Published Feb 21, 2019

In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9079

Published Jun 11, 2018

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users…

CVSS 7.5 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Showing 1-25 of 41 CVEsPage 1 of 2