torproject records
53 published records for vendor torproject.
Researcher profile
- Entered KEV
- 1 · 1.9%
- Weaponized
- 1 · 1.9%
- Pre-auth RCE
- 0
- With a fix record
- 88.7%
- Median publish → KEV
- 1837 days
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-617 Reachable Assertion4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-20 Improper Input Validation2
- CWE-476 NULL Pointer Dereference2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
53 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
86Now | CVE-2016-9079Weaponized | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | High7.5 | KEV | 87.4% | Jun 11, 2018 |
40Plan | CVE-2018-16983No exploit | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/htmlnoscript · noscript | Critical9.8 | — | 3.1% | Sep 13, 2018 |
37Monitor | CVE-2026-77642No exploit | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest typetorproject · tor · CWE-787 | Critical9.3 | — | 0.4% | Aug 20, 2026 |
36Monitor | CVE-2026-44603No exploit | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.torproject · tor · CWE-193 | Critical9.1 | — | 0.6% | May 7, 2026 |
36Monitor | CVE-2026-44597No exploit | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Critical9.1 | — | 0.6% | May 6, 2026 |
36Monitor | CVE-2026-77638No exploit | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonatorproject · tor · CWE-362 | Critical9.0 | — | 0.3% | Aug 20, 2026 |
34Monitor | CVE-2018-0491Proof of concept | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.torproject · tor · CWE-416 | High7.5 | — | 14.8% | Mar 5, 2018 |
32Monitor | CVE-2026-77641No exploit | tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.torproject · tor · CWE-252 | High8.2 | — | 0.4% | Aug 20, 2026 |
32Monitor | CVE-2026-77584No exploit | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.torproject · tor · CWE-821 | High8.2 | — | 0.3% | Aug 20, 2026 |
31Monitor | CVE-2019-8955No exploit | In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Totorproject · tor · CWE-770 | High7.5 | — | 4.6% | Feb 21, 2019 |
31Monitor | CVE-2020-10592No exploit | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)torproject · tor | High7.5 | — | 3.2% | Mar 23, 2020 |
31Monitor | CVE-2016-1254No exploit | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.torproject · tor · CWE-119 | High7.5 | — | 3.0% | Dec 5, 2017 |
31Monitor | CVE-2021-34548No exploit | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.torproject · tor · CWE-290 | High7.5 | — | 2.7% | Jun 29, 2021 |
31Monitor | CVE-2018-0490No exploit | An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.torproject · tor · CWE-476 | High7.5 | — | 2.6% | Mar 5, 2018 |
31Monitor | CVE-2017-0375No exploit | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_ftorproject · tor · CWE-617 | High7.5 | — | 2.6% | Jun 9, 2017 |
31Monitor | CVE-2017-0377No exploit | Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allowtorproject · tor · CWE-200 | High7.5 | — | 2.4% | Jul 2, 2017 |
31Monitor | CVE-2020-10593No exploit | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aktorproject · tor · CWE-401 | High7.5 | — | 2.3% | Mar 23, 2020 |
31Monitor | CVE-2015-2689No exploit | Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, torproject · tor · CWE-20 | High7.5 | — | 2.2% | Jan 24, 2020 |
31Monitor | CVE-2015-2688No exploit | buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layotorproject · tor · CWE-755 | High7.5 | — | 2.2% | Jan 24, 2020 |
31Monitor | CVE-2017-0376No exploit | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_procetorproject · tor · CWE-617 | High7.5 | — | 2.2% | Jun 9, 2017 |
31Monitor | CVE-2016-8860No exploit | Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,torproject · tor · CWE-119 | High7.5 | — | 1.9% | Jan 4, 2017 |
31Monitor | CVE-2021-38385No exploit | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatiotorproject · tor · CWE-617 | High7.5 | — | 1.7% | Aug 30, 2021 |
31Monitor | CVE-2021-28089No exploit | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.torproject · tor · CWE-400 | High7.5 | — | 1.7% | Mar 19, 2021 |
30Monitor | CVE-2021-34549No exploit | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.torproject · tor · CWE-400 | High7.5 | — | 1.6% | Jun 29, 2021 |
30Monitor | CVE-2021-34550No exploit | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.torproject · tor · CWE-119 | High7.5 | — | 1.6% | Jun 29, 2021 |
- CVE-2016-907986Now
A use-after-free vulnerability in SVG Animation has been discovered.
HighCVSS 7.5KEVWeaponizedEPSS 87%debian · debian linuxJun 11, 2018
- CVE-2018-1698340Plan
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html
CriticalCVSS 9.8No exploitEPSS 3%noscript · noscriptSep 13, 2018
- CVE-2026-7764237Monitor
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type
CriticalCVSS 9.3No exploitEPSS 0%torproject · torAug 20, 2026
- CVE-2026-4460336Monitor
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CriticalCVSS 9.1No exploitEPSS 1%torproject · torMay 7, 2026
- CVE-2026-4459736Monitor
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
CriticalCVSS 9.1No exploitEPSS 1%torproject · torMay 6, 2026
- CVE-2026-7763836Monitor
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersona
CriticalCVSS 9.0No exploitEPSS 0%torproject · torAug 20, 2026
- CVE-2018-049134Monitor
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
HighCVSS 7.5Proof of conceptEPSS 15%torproject · torMar 5, 2018
- CVE-2026-7764132Monitor
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.
HighCVSS 8.2No exploitEPSS 0%torproject · torAug 20, 2026
- CVE-2026-7758432Monitor
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.
HighCVSS 8.2No exploitEPSS 0%torproject · torAug 20, 2026
- CVE-2019-895531Monitor
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against To
HighCVSS 7.5No exploitEPSS 5%torproject · torFeb 21, 2019
- CVE-2020-1059231Monitor
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)
HighCVSS 7.5No exploitEPSS 3%torproject · torMar 23, 2020
- CVE-2016-125431Monitor
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
HighCVSS 7.5No exploitEPSS 3%torproject · torDec 5, 2017
- CVE-2021-3454831Monitor
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.
HighCVSS 7.5No exploitEPSS 3%torproject · torJun 29, 2021
- CVE-2018-049031Monitor
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.
HighCVSS 7.5No exploitEPSS 3%torproject · torMar 5, 2018
- CVE-2017-037531Monitor
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_f
HighCVSS 7.5No exploitEPSS 3%torproject · torJun 9, 2017
- CVE-2017-037731Monitor
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow
HighCVSS 7.5No exploitEPSS 2%torproject · torJul 2, 2017
- CVE-2020-1059331Monitor
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), ak
HighCVSS 7.5No exploitEPSS 2%torproject · torMar 23, 2020
- CVE-2015-268931Monitor
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load,
HighCVSS 7.5No exploitEPSS 2%torproject · torJan 24, 2020
- CVE-2015-268831Monitor
buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layo
HighCVSS 7.5No exploitEPSS 2%torproject · torJan 24, 2020
- CVE-2017-037631Monitor
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_proce
HighCVSS 7.5No exploitEPSS 2%torproject · torJun 9, 2017
- CVE-2016-886031Monitor
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,
HighCVSS 7.5No exploitEPSS 2%torproject · torJan 4, 2017
- CVE-2021-3838531Monitor
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatio
HighCVSS 7.5No exploitEPSS 2%torproject · torAug 30, 2021
- CVE-2021-2808931Monitor
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
HighCVSS 7.5No exploitEPSS 2%torproject · torMar 19, 2021
- CVE-2021-3454930Monitor
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.
HighCVSS 7.5No exploitEPSS 2%torproject · torJun 29, 2021
- CVE-2021-3455030Monitor
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.
HighCVSS 7.5No exploitEPSS 2%torproject · torJun 29, 2021