VYPR
Vendor

Torproject

Products
2
CVEs
72
Across products
74
Status
Private

Products

2

Recent CVEs

72
View all 72 CVEs →
  • CVE-2016-9079HigKEVJun 11, 2018
    risk 0.71cvss 7.5epss 0.87

    A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird <…

  • CVE-2018-16983CriSep 13, 2018
    risk 0.64cvss 9.8epss 0.03

    NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.

  • CVE-2026-77638HigAug 20, 2026
    risk 0.58cvss 8.9epss 0.00

    Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

  • CVE-2018-0491HigMar 5, 2018
    risk 0.53cvss 7.5epss 0.15

    A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.

  • CVE-2017-8823HigDec 3, 2017
    risk 0.53cvss 8.1epss 0.02

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka…

  • CVE-2026-77642HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

  • CVE-2022-33903HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

  • CVE-2021-38385HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

  • CVE-2021-34550HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

  • CVE-2021-34549HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.

  • CVE-2021-34548HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

  • CVE-2021-28089HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

  • CVE-2020-15572HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

  • CVE-2020-10593HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same…

  • CVE-2020-10592HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.03

    Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.

  • CVE-2015-2929HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.01

    The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.

  • CVE-2015-2928HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.01

    The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.

  • CVE-2015-2689HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

  • CVE-2015-2688HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

  • CVE-2019-8955HigFeb 21, 2019
    risk 0.49cvss 7.5epss 0.05

    In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.