Tor / Tor
62 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-2688 | buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows r… | HIGH | 7.5 | Jan 24, 2020 |
| CVE-2015-2689 | Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote… | HIGH | 7.5 | Jan 24, 2020 |
| CVE-2015-2929 | The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a deni… | HIGH | 7.5 | Jan 24, 2020 |
| CVE-2015-2928 | The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a de… | HIGH | 7.5 | Jan 24, 2020 |
| CVE-2017-8823 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free… | HIGH | 8.1 | Dec 3, 2017 |
| CVE-2017-8822 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incomple… | LOW | 3.7 | Dec 3, 2017 |
| CVE-2017-8821 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a de… | HIGH | 7.5 | Dec 3, 2017 |
| CVE-2017-8820 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause… | HIGH | 7.5 | Dec 3, 2017 |
| CVE-2017-8819 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protectio… | HIGH | 7.5 | Dec 3, 2017 |
| CVE-2012-3519 | routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attac… | MEDIUM | 5.0 | Aug 26, 2012 |
| CVE-2012-3518 | The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote… | MEDIUM | 5.0 | Aug 26, 2012 |
| CVE-2012-3517 | Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to fa… | MEDIUM | 5.0 | Aug 26, 2012 |
| CVE-2011-4897 | Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows re… | MEDIUM | 4.3 | Dec 23, 2011 |
| CVE-2011-4896 | Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attacker… | MEDIUM | 4.3 | Dec 23, 2011 |
| CVE-2011-4895 | Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for rem… | MEDIUM | 4.3 | Dec 23, 2011 |
| CVE-2011-4894 | Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for r… | MEDIUM | 4.3 | Dec 23, 2011 |
| CVE-2011-2778 | Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitra… | HIGH | 7.6 | Dec 23, 2011 |
| CVE-2011-2769 | Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it init… | MEDIUM | 4.3 | Dec 23, 2011 |
| CVE-2011-2768 | Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to b… | MEDIUM | 5.8 | Dec 23, 2011 |
| CVE-2011-1924 | Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory author… | MEDIUM | 5.0 | Jun 14, 2011 |
| CVE-2011-0493 | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors… | MEDIUM | 5.0 | Jan 19, 2011 |
| CVE-2011-0492 | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that t… | MEDIUM | 5.0 | Jan 19, 2011 |
| CVE-2011-0491 | The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might… | MEDIUM | 5.0 | Jan 19, 2011 |
| CVE-2011-0490 | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denia… | MEDIUM | 5.0 | Jan 19, 2011 |
| CVE-2011-0427 | Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and… | MEDIUM | 6.8 | Jan 19, 2011 |
Showing 1 to 25 of 62 CVEs