Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
torproject tor vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2015-2688
buf_pullup in Tor prior to 0.2.4.26 and 0.2.5.x prior to 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Torproject Tor
7.5
CVSSv3
CVE-2015-2689
Tor prior to 0.2.4.26 and 0.2.5.x prior to 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Torproject Tor
7.5
CVSSv3
CVE-2015-2928
The Hidden Service (HS) server implementation in Tor prior to 0.2.4.27, 0.2.5.x prior to 0.2.5.12, and 0.2.6.x prior to 0.2.6.7 allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
Torproject Tor
7.5
CVSSv3
CVE-2015-2929
The Hidden Service (HS) client implementation in Tor prior to 0.2.4.27, 0.2.5.x prior to 0.2.5.12, and 0.2.6.x prior to 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
Torproject Tor
7.5
CVSSv3
CVE-2019-8955
In Tor prior to 0.3.3.12, 0.3.4.x prior to 0.3.4.11, 0.3.5.x prior to 0.3.5.8, and 0.4.x prior to 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
Torproject Tor 0.3.4.5
Torproject Tor 0.3.4.6
Torproject Tor 0.3.5.4
Torproject Tor 0.3.5.5
Torproject Tor 0.3.4.1
Torproject Tor 0.3.4.2
Torproject Tor 0.3.5.0
Torproject Tor 0.3.5.1
Torproject Tor
Torproject Tor 0.3.4.0
Torproject Tor 0.3.4.7
Torproject Tor 0.3.5.6
Torproject Tor 0.3.5.7
Torproject Tor 0.4.0.1
Torproject Tor 0.3.4.3
Torproject Tor 0.3.4.4
Torproject Tor 0.3.5.2
Torproject Tor 0.3.5.3
7.5
CVSSv3
CVE-2018-0490
An issue exists in Tor prior to 0.2.9.15, 0.3.1.x prior to 0.3.1.10, and 0.3.2.x prior to 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote malicious users to cause a denial of service (NULL pointer dereference and directory-authority crash)...
Torproject Tor 0.3.1.4
Torproject Tor 0.3.1.3
Torproject Tor 0.3.1.2
Torproject Tor 0.3.1.1
Torproject Tor 0.3.2.6
Torproject Tor 0.3.2.5
Torproject Tor 0.3.2.4
Torproject Tor 0.3.2.3
Torproject Tor 0.3.2.8
Torproject Tor 0.3.2.1
Torproject Tor 0.3.1.6
Torproject Tor 0.3.1.5
Torproject Tor 0.3.2.7
Torproject Tor 0.3.2.9
Torproject Tor 0.3.2.2
Torproject Tor
Debian Debian Linux 9.0
7.5
CVSSv3
CVE-2018-0491
A use-after-free issue exists in Tor 0.3.2.x prior to 0.3.2.10. It allows remote malicious users to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.
Torproject Tor
1 EDB exploit
7.5
CVSSv3
CVE-2016-1254
Tor prior to 0.2.8.12 might allow remote malicious users to cause a denial of service (client crash) via a crafted hidden service descriptor.
Torproject Tor
Opensuse Project Leap 42.1
Debian Debian Linux 8.0
Fedoraproject Fedora 25
Fedoraproject Fedora 24
Debian Debian Linux 9.0
Opensuse Leap 42.2
Opensuse Opensuse 13.2
7.5
CVSSv3
CVE-2017-0377
Tor 0.3.x prior to 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote malicious users to defeat intended anonymity properties by leveraging the existence of large families.
Torproject Tor 0.3.0.5
Torproject Tor 0.3.0.4
Torproject Tor 0.3.0.3
Torproject Tor 0.3.0.2
Torproject Tor 0.3.0.8
Torproject Tor 0.3.0.6
Torproject Tor 0.3.0.1
Torproject Tor 0.3.0.7
7.5
CVSSv3
CVE-2017-0375
The hidden-service feature in Tor prior to 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
Torproject Tor
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »