Tor
Torproject · 48 CVEs
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected s…
Aug 20, 2026
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of r…
Aug 20, 2026
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncat…
Aug 20, 2026
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-str…
Aug 20, 2026
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-…
Aug 20, 2026
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg re…
Aug 20, 2026
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A…
Aug 20, 2026
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
May 7, 2026
Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
May 7, 2026
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close…
May 7, 2026
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-20…
May 7, 2026
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
May 7, 2026
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload…
May 7, 2026
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not t…
Jan 14, 2023
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
Jul 17, 2022
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers t…
Feb 26, 2022
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-…
Aug 30, 2021
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-o…
Jun 29, 2021
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circu…
Jun 29, 2021
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to…
Jun 29, 2021
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka T…
Mar 19, 2021
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka…
Mar 19, 2021
Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor…
Jul 15, 2020
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Serv…
Mar 23, 2020
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Serv…
Mar 23, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-77642 | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor fo… | CRITICAL | 0.35% | Aug 20, 2026 |
| CVE-2026-77641 | tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignore… | HIGH | 0.35% | Aug 20, 2026 |
| CVE-2026-77640 | tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, ca… | MEDIUM | 0.38% | Aug 20, 2026 |
| CVE-2026-77639 | Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream det… | MEDIUM | 0.39% | Aug 20, 2026 |
| CVE-2026-77638 | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion servi… | CRITICAL | 0.30% | Aug 20, 2026 |
| CVE-2026-77587 | Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked le… | HIGH | 0.40% | Aug 20, 2026 |
| CVE-2026-77584 | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMM… | HIGH | 0.25% | Aug 20, 2026 |
| CVE-2026-44603 | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. | CRITICAL | 0.63% | May 7, 2026 |
| CVE-2026-44602 | Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. | HIGH | 0.60% | May 7, 2026 |
| CVE-2026-44601 | Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. | HIGH | 0.60% | May 7, 2026 |
| CVE-2026-44600 | Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010. | MEDIUM | 0.51% | May 7, 2026 |
| CVE-2026-44599 | Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008. | MEDIUM | 0.40% | May 7, 2026 |
| CVE-2026-44597 | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | CRITICAL | 0.63% | May 7, 2026 |
| CVE-2023-23589 | The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022… | MEDIUM | 0.83% | Jan 14, 2023 |
| CVE-2022-33903 | Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation. | HIGH | 1.34% | Jul 17, 2022 |
| CVE-2021-46702 | Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature… | MEDIUM | 0.39% | Feb 26, 2022 |
| CVE-2021-38385 | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a rem… | HIGH | 1.69% | Aug 30, 2021 |
| CVE-2021-34550 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client cra… | HIGH | 1.56% | Jun 29, 2021 |
| CVE-2021-34549 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can t… | HIGH | 1.61% | Jun 29, 2021 |
| CVE-2021-34548 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for… | HIGH | 2.72% | Jun 29, 2021 |
| CVE-2021-28090 | Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. | MEDIUM | 2.10% | Mar 19, 2021 |
| CVE-2021-28089 | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. | HIGH | 1.67% | Mar 19, 2021 |
| CVE-2020-15572 | Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network… | HIGH | 1.40% | Jul 15, 2020 |
| CVE-2020-10593 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. T… | HIGH | 2.34% | Mar 23, 2020 |
| CVE-2020-10592 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-00… | HIGH | 3.23% | Mar 23, 2020 |
Showing 1 to 25 of 48 CVEs