Записи torproject
53 опубликованных записей вендора torproject.
Профиль для исследователя
- Попали в KEV
- 1 · 1,9 %
- С эксплойтом
- 1 · 1,9 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 88,7 %
- Медиана: публикация → KEV
- 1837 дн.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-617 Reachable Assertion4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-20 Improper Input Validation2
- CWE-476 NULL Pointer Dereference2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
53 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
86Срочно | CVE-2016-9079Готовый эксплойт | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | Высокая7,5 | KEV | 87,4 % | 11 июн. 2018 г. |
40В плане | CVE-2018-16983Эксплойта нет | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/htmlnoscript · noscript | Критическая9,8 | — | 3,1 % | 13 сент. 2018 г. |
37Наблюдать | CVE-2026-77642Эксплойта нет | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest typetorproject · tor · CWE-787 | Критическая9,3 | — | 0,4 % | 20 авг. 2026 г. |
36Наблюдать | CVE-2026-44603Эксплойта нет | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.torproject · tor · CWE-193 | Критическая9,1 | — | 0,6 % | 7 мая 2026 г. |
36Наблюдать | CVE-2026-44597Эксплойта нет | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Критическая9,1 | — | 0,6 % | 6 мая 2026 г. |
36Наблюдать | CVE-2026-77638Эксплойта нет | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonatorproject · tor · CWE-362 | Критическая9,0 | — | 0,3 % | 20 авг. 2026 г. |
34Наблюдать | CVE-2018-0491Proof of concept | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.torproject · tor · CWE-416 | Высокая7,5 | — | 14,8 % | 5 мар. 2018 г. |
32Наблюдать | CVE-2026-77641Эксплойта нет | tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.torproject · tor · CWE-252 | Высокая8,2 | — | 0,4 % | 20 авг. 2026 г. |
32Наблюдать | CVE-2026-77584Эксплойта нет | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.torproject · tor · CWE-821 | Высокая8,2 | — | 0,3 % | 20 авг. 2026 г. |
31Наблюдать | CVE-2019-8955Эксплойта нет | In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Totorproject · tor · CWE-770 | Высокая7,5 | — | 4,6 % | 21 февр. 2019 г. |
31Наблюдать | CVE-2020-10592Эксплойта нет | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)torproject · tor | Высокая7,5 | — | 3,2 % | 23 мар. 2020 г. |
31Наблюдать | CVE-2016-1254Эксплойта нет | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.torproject · tor · CWE-119 | Высокая7,5 | — | 3,0 % | 5 дек. 2017 г. |
31Наблюдать | CVE-2021-34548Эксплойта нет | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.torproject · tor · CWE-290 | Высокая7,5 | — | 2,7 % | 29 июн. 2021 г. |
31Наблюдать | CVE-2018-0490Эксплойта нет | An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.torproject · tor · CWE-476 | Высокая7,5 | — | 2,6 % | 5 мар. 2018 г. |
31Наблюдать | CVE-2017-0375Эксплойта нет | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_ftorproject · tor · CWE-617 | Высокая7,5 | — | 2,6 % | 9 июн. 2017 г. |
31Наблюдать | CVE-2017-0377Эксплойта нет | Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allowtorproject · tor · CWE-200 | Высокая7,5 | — | 2,4 % | 2 июл. 2017 г. |
31Наблюдать | CVE-2020-10593Эксплойта нет | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aktorproject · tor · CWE-401 | Высокая7,5 | — | 2,3 % | 23 мар. 2020 г. |
31Наблюдать | CVE-2015-2689Эксплойта нет | Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, torproject · tor · CWE-20 | Высокая7,5 | — | 2,2 % | 24 янв. 2020 г. |
31Наблюдать | CVE-2015-2688Эксплойта нет | buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layotorproject · tor · CWE-755 | Высокая7,5 | — | 2,2 % | 24 янв. 2020 г. |
31Наблюдать | CVE-2017-0376Эксплойта нет | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_procetorproject · tor · CWE-617 | Высокая7,5 | — | 2,2 % | 9 июн. 2017 г. |
31Наблюдать | CVE-2016-8860Эксплойта нет | Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,torproject · tor · CWE-119 | Высокая7,5 | — | 1,9 % | 4 янв. 2017 г. |
31Наблюдать | CVE-2021-38385Эксплойта нет | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatiotorproject · tor · CWE-617 | Высокая7,5 | — | 1,7 % | 30 авг. 2021 г. |
31Наблюдать | CVE-2021-28089Эксплойта нет | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.torproject · tor · CWE-400 | Высокая7,5 | — | 1,7 % | 19 мар. 2021 г. |
30Наблюдать | CVE-2021-34549Эксплойта нет | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.torproject · tor · CWE-400 | Высокая7,5 | — | 1,6 % | 29 июн. 2021 г. |
30Наблюдать | CVE-2021-34550Эксплойта нет | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.torproject · tor · CWE-119 | Высокая7,5 | — | 1,6 % | 29 июн. 2021 г. |
- CVE-2016-907986Срочно
A use-after-free vulnerability in SVG Animation has been discovered.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %debian · debian linux11 июн. 2018 г.
- CVE-2018-1698340В плане
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %noscript · noscript13 сент. 2018 г.
- CVE-2026-7764237Наблюдать
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %torproject · tor20 авг. 2026 г.
- CVE-2026-4460336Наблюдать
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %torproject · tor7 мая 2026 г.
- CVE-2026-4459736Наблюдать
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %torproject · tor6 мая 2026 г.
- CVE-2026-7763836Наблюдать
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersona
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %torproject · tor20 авг. 2026 г.
- CVE-2018-049134Наблюдать
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %torproject · tor5 мар. 2018 г.
- CVE-2026-7764132Наблюдать
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %torproject · tor20 авг. 2026 г.
- CVE-2026-7758432Наблюдать
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %torproject · tor20 авг. 2026 г.
- CVE-2019-895531Наблюдать
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against To
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %torproject · tor21 февр. 2019 г.
- CVE-2020-1059231Наблюдать
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor23 мар. 2020 г.
- CVE-2016-125431Наблюдать
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor5 дек. 2017 г.
- CVE-2021-3454831Наблюдать
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor29 июн. 2021 г.
- CVE-2018-049031Наблюдать
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor5 мар. 2018 г.
- CVE-2017-037531Наблюдать
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_f
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor9 июн. 2017 г.
- CVE-2017-037731Наблюдать
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor2 июл. 2017 г.
- CVE-2020-1059331Наблюдать
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), ak
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor23 мар. 2020 г.
- CVE-2015-268931Наблюдать
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor24 янв. 2020 г.
- CVE-2015-268831Наблюдать
buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layo
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor24 янв. 2020 г.
- CVE-2017-037631Наблюдать
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_proce
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor9 июн. 2017 г.
- CVE-2016-886031Наблюдать
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor4 янв. 2017 г.
- CVE-2021-3838531Наблюдать
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatio
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor30 авг. 2021 г.
- CVE-2021-2808931Наблюдать
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor19 мар. 2021 г.
- CVE-2021-3454930Наблюдать
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor29 июн. 2021 г.
- CVE-2021-3455030Наблюдать
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %torproject · tor29 июн. 2021 г.