Tor

Torproject · 48 CVEs

CVE-2026-77642
CRITICAL

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected s…

Aug 20, 2026

CVE-2026-77641
HIGH

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of r…

Aug 20, 2026

CVE-2026-77640
MEDIUM

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncat…

Aug 20, 2026

CVE-2026-77639
MEDIUM

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-str…

Aug 20, 2026

CVE-2026-77638
CRITICAL

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-…

Aug 20, 2026

CVE-2026-77587
HIGH

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg re…

Aug 20, 2026

CVE-2026-77584
HIGH

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A…

Aug 20, 2026

CVE-2026-44603
CRITICAL

Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.

May 7, 2026

CVE-2026-44602
HIGH

Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.

May 7, 2026

CVE-2026-44601
HIGH

Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close…

May 7, 2026

CVE-2026-44600
MEDIUM

Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-20…

May 7, 2026

CVE-2026-44599
MEDIUM

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

May 7, 2026

CVE-2026-44597
CRITICAL

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload…

May 7, 2026

CVE-2023-23589
MEDIUM

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not t…

Jan 14, 2023

CVE-2022-33903
HIGH

Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

Jul 17, 2022

CVE-2021-46702
MEDIUM

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers t…

Feb 26, 2022

CVE-2021-38385
HIGH

Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-…

Aug 30, 2021

CVE-2021-34550
HIGH

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-o…

Jun 29, 2021

CVE-2021-34549
HIGH

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circu…

Jun 29, 2021

CVE-2021-34548
HIGH

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to…

Jun 29, 2021

CVE-2021-28090
MEDIUM

Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka T…

Mar 19, 2021

CVE-2021-28089
HIGH

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka…

Mar 19, 2021

CVE-2020-15572
HIGH

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor…

Jul 15, 2020

CVE-2020-10593
HIGH

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Serv…

Mar 23, 2020

CVE-2020-10592
HIGH

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Serv…

Mar 23, 2020

Showing 1 to 25 of 48 CVEs