VYPR

Vendor CVEs

Torproject

All CVEs

64 total · sorted by risk
  • CVE-2012-4922Sep 14, 2012
    risk 0.00cvss epss 0.02

    The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different…

  • CVE-2012-4419Sep 14, 2012
    risk 0.00cvss epss 0.02

    The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy…

  • CVE-2011-1924Jun 14, 2011
    risk 0.00cvss epss 0.03

    Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.

  • CVE-2011-0016Jan 19, 2011
    risk 0.00cvss epss 0.00

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.

  • CVE-2009-0939Mar 18, 2009
    risk 0.00cvss epss 0.02

    Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.

  • CVE-2009-0938Mar 18, 2009
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."

  • CVE-2009-0937Mar 18, 2009
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors.

  • CVE-2009-0936Mar 18, 2009
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."

  • CVE-2009-0654Feb 20, 2009
    risk 0.00cvss epss 0.02

    Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell,…

  • CVE-2009-0414Feb 3, 2009
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.

  • CVE-2008-5398Dec 9, 2008
    risk 0.00cvss epss 0.02

    Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the…

  • CVE-2008-5397Dec 9, 2008
    risk 0.00cvss epss 0.00

    Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.

  • CVE-2007-4096Jul 30, 2007
    risk 0.00cvss epss 0.02

    Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2007-4099Jul 30, 2007
    risk 0.00cvss epss 0.02

    Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks.

Page 2 of 2