tor records
57 published records for vendor tor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 93%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-189 Numeric Errors1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
57 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2010-1676No exploit | Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (dator · tor · CWE-119 | Critical10.0 | — | 7.9% | Dec 21, 2010 |
41Plan | CVE-2009-0414No exploit | Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.tor · tor · CWE-399 | Critical10.0 | — | 3.0% | Feb 3, 2009 |
41Plan | CVE-2009-0939No exploit | Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," astor · tor | Critical10.0 | — | 2.1% | Mar 17, 2009 |
38Monitor | CVE-2008-5398No exploit | Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay istor · tor · CWE-264 | Critical9.3 | — | 2.0% | Dec 8, 2008 |
31Monitor | CVE-2011-2778No exploit | Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possitor · tor · CWE-119 | High7.6 | — | 3.8% | Dec 22, 2011 |
31Monitor | CVE-2006-3409No exploit | Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffertor · tor | High7.5 | — | 3.7% | Jul 6, 2006 |
28Monitor | CVE-2011-0427No exploit | Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (metor · tor · CWE-119 | Medium6.8 | — | 4.4% | Jan 19, 2011 |
28Monitor | CVE-2008-5397No exploit | Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain priviltor · tor · CWE-264 | High7.2 | — | 0.4% | Dec 8, 2008 |
26Monitor | CVE-2007-4097No exploit | Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitivtor · tor | Medium6.4 | — | 2.2% | Jul 30, 2007 |
26Monitor | CVE-2006-3412No exploit | Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictiontor · tor | Medium6.4 | — | 2.2% | Jul 6, 2006 |
26Monitor | CVE-2006-3417No exploit | Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred overtor · tor | Medium6.4 | — | 2.1% | Jul 6, 2006 |
26Monitor | CVE-2006-3415No exploit | Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITMtor · tor | Medium6.4 | — | 2.0% | Jul 6, 2006 |
25Monitor | CVE-2007-4174Proof of concept | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers tor · tor · CWE-264 | Medium5.8 | — | 6.2% | Aug 7, 2007 |
25Monitor | CVE-2006-3407No exploit | Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.tor · tor | Medium6.4 | — | 1.5% | Jul 6, 2006 |
25Monitor | CVE-2006-3411No exploit | TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fotor · tor | Medium6.4 | — | 1.3% | Jul 6, 2006 |
24Monitor | CVE-2007-4096No exploit | Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vetor · tor | Medium5.8 | — | 2.0% | Jul 30, 2007 |
24Monitor | CVE-2007-4099No exploit | Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers withtor · tor | Medium5.8 | — | 1.9% | Jul 30, 2007 |
24Monitor | CVE-2007-4098No exploit | Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tortor · tor | Medium5.8 | — | 1.9% | Jul 30, 2007 |
23Monitor | CVE-2011-2768No exploit | Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allowstor · tor · CWE-264 | Medium5.8 | — | 0.7% | Dec 22, 2011 |
21Monitor | CVE-2011-0015No exploit | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allowtor · tor · CWE-20 | Medium5.0 | — | 3.1% | Jan 19, 2011 |
21Monitor | CVE-2006-0414No exploit | Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses tor · tor | Medium5.0 | — | 3.0% | Jan 25, 2006 |
21Monitor | CVE-2011-1924No exploit | Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servictor · tor · CWE-119 | Medium5.0 | — | 2.8% | Jun 14, 2011 |
21Monitor | CVE-2012-3517No exploit | Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vetor · tor · CWE-399 | Medium5.0 | — | 2.8% | Aug 25, 2012 |
21Monitor | CVE-2012-3518No exploit | The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, wtor · tor · CWE-119 | Medium5.0 | — | 2.8% | Aug 25, 2012 |
21Monitor | CVE-2011-0492No exploit | Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exitor · tor · CWE-399 | Medium5.0 | — | 2.5% | Jan 19, 2011 |
- CVE-2010-167642Plan
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (da
CriticalCVSS 10.0No exploitEPSS 8%tor · torDec 21, 2010
- CVE-2009-041441Plan
Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
CriticalCVSS 10.0No exploitEPSS 3%tor · torFeb 3, 2009
- CVE-2009-093941Plan
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as
CriticalCVSS 10.0No exploitEPSS 2%tor · torMar 17, 2009
- CVE-2008-539838Monitor
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay is
CriticalCVSS 9.3No exploitEPSS 2%tor · torDec 8, 2008
- CVE-2011-277831Monitor
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possi
HighCVSS 7.6No exploitEPSS 4%tor · torDec 22, 2011
- CVE-2006-340931Monitor
Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer
HighCVSS 7.5No exploitEPSS 4%tor · torJul 6, 2006
- CVE-2011-042728Monitor
Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (me
MediumCVSS 6.8No exploitEPSS 4%tor · torJan 19, 2011
- CVE-2008-539728Monitor
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privil
HighCVSS 7.2No exploitEPSS 0%tor · torDec 8, 2008
- CVE-2007-409726Monitor
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitiv
MediumCVSS 6.4No exploitEPSS 2%tor · torJul 30, 2007
- CVE-2006-341226Monitor
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restriction
MediumCVSS 6.4No exploitEPSS 2%tor · torJul 6, 2006
- CVE-2006-341726Monitor
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over
MediumCVSS 6.4No exploitEPSS 2%tor · torJul 6, 2006
- CVE-2006-341526Monitor
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM
MediumCVSS 6.4No exploitEPSS 2%tor · torJul 6, 2006
- CVE-2007-417425Monitor
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers
MediumCVSS 5.8Proof of conceptEPSS 6%tor · torAug 7, 2007
- CVE-2006-340725Monitor
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
MediumCVSS 6.4No exploitEPSS 2%tor · torJul 6, 2006
- CVE-2006-341125Monitor
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier fo
MediumCVSS 6.4No exploitEPSS 1%tor · torJul 6, 2006
- CVE-2007-409624Monitor
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified ve
MediumCVSS 5.8No exploitEPSS 2%tor · torJul 30, 2007
- CVE-2007-409924Monitor
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with
MediumCVSS 5.8No exploitEPSS 2%tor · torJul 30, 2007
- CVE-2007-409824Monitor
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor
MediumCVSS 5.8No exploitEPSS 2%tor · torJul 30, 2007
- CVE-2011-276823Monitor
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows
MediumCVSS 5.8No exploitEPSS 1%tor · torDec 22, 2011
- CVE-2011-001521Monitor
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allow
MediumCVSS 5.0No exploitEPSS 3%tor · torJan 19, 2011
- CVE-2006-041421Monitor
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses
MediumCVSS 5.0No exploitEPSS 3%tor · torJan 25, 2006
- CVE-2011-192421Monitor
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of servic
MediumCVSS 5.0No exploitEPSS 3%tor · torJun 14, 2011
- CVE-2012-351721Monitor
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via ve
MediumCVSS 5.0No exploitEPSS 3%tor · torAug 25, 2012
- CVE-2012-351821Monitor
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, w
MediumCVSS 5.0No exploitEPSS 3%tor · torAug 25, 2012
- CVE-2011-049221Monitor
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exi
MediumCVSS 5.0No exploitEPSS 3%tor · torJan 19, 2011