VYPR

Tor

by Tor

Source repositories

CVEs (73)

  • CVE-2018-0491HigMar 5, 2018
    risk 0.53cvss 7.5epss 0.15

    A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.

  • CVE-2022-33903HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

  • CVE-2021-38385HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

  • CVE-2021-34550HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

  • CVE-2021-34549HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.

  • CVE-2021-34548HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

  • CVE-2020-15572HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

  • CVE-2018-0490HigMar 5, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash)…

  • CVE-2007-4174Aug 7, 2007
    risk 0.03cvss —epss 0.06

    Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands…

  • CVE-2010-1676Dec 22, 2010
    risk 0.01cvss —epss 0.08

    Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

  • CVE-2023-23589MedJan 14, 2023
    risk 0.00cvss 6.5epss 0.01

    The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

  • CVE-2014-5117Jul 30, 2014
    risk 0.00cvss —epss 0.02

    Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of…

  • CVE-2012-2250Feb 3, 2014
    risk 0.00cvss —epss 0.01

    Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.

  • CVE-2012-2249Feb 3, 2014
    risk 0.00cvss —epss 0.01

    Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.

  • CVE-2013-7295Jan 17, 2014
    risk 0.00cvss —epss 0.02

    Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it…

  • CVE-2012-5573Jan 1, 2013
    risk 0.00cvss —epss 0.03

    The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass…

  • CVE-2012-4922Sep 14, 2012
    risk 0.00cvss —epss 0.02

    The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different…

  • CVE-2012-4419Sep 14, 2012
    risk 0.00cvss —epss 0.02

    The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy…

  • CVE-2012-3519Aug 26, 2012
    risk 0.00cvss —epss 0.02

    routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-channel attack.

  • CVE-2012-3518Aug 26, 2012
    risk 0.00cvss —epss 0.03

    The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2)…

Page 1 of 4