torproject kayıtları
torproject üreticisine ait 53 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,9
- Silahlaştırılmış
- 1 · %1,9
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %88,7
- Yayından KEV’e ortanca
- 1837 gün
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-617 Reachable Assertion4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-20 Improper Input Validation2
- CWE-476 NULL Pointer Dereference2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
53 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
86Hemen | CVE-2016-9079Silahlaştırılmış | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | Yüksek7,5 | KEV | %87,4 | 11 Haz 2018 |
40Planlayın | CVE-2018-16983İstismar yok | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/htmlnoscript · noscript | Kritik9,8 | — | %3,1 | 13 Eyl 2018 |
37İzleyin | CVE-2026-77642İstismar yok | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest typetorproject · tor · CWE-787 | Kritik9,3 | — | %0,4 | 20 Ağu 2026 |
36İzleyin | CVE-2026-44603İstismar yok | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.torproject · tor · CWE-193 | Kritik9,1 | — | %0,6 | 7 May 2026 |
36İzleyin | CVE-2026-44597İstismar yok | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Kritik9,1 | — | %0,6 | 6 May 2026 |
36İzleyin | CVE-2026-77638İstismar yok | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonatorproject · tor · CWE-362 | Kritik9,0 | — | %0,3 | 20 Ağu 2026 |
34İzleyin | CVE-2018-0491Kavram kanıtı | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.torproject · tor · CWE-416 | Yüksek7,5 | — | %14,8 | 5 Mar 2018 |
32İzleyin | CVE-2026-77641İstismar yok | tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.torproject · tor · CWE-252 | Yüksek8,2 | — | %0,4 | 20 Ağu 2026 |
32İzleyin | CVE-2026-77584İstismar yok | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.torproject · tor · CWE-821 | Yüksek8,2 | — | %0,3 | 20 Ağu 2026 |
31İzleyin | CVE-2019-8955İstismar yok | In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Totorproject · tor · CWE-770 | Yüksek7,5 | — | %4,6 | 21 Şub 2019 |
31İzleyin | CVE-2020-10592İstismar yok | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)torproject · tor | Yüksek7,5 | — | %3,2 | 23 Mar 2020 |
31İzleyin | CVE-2016-1254İstismar yok | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.torproject · tor · CWE-119 | Yüksek7,5 | — | %3,0 | 5 Ara 2017 |
31İzleyin | CVE-2021-34548İstismar yok | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.torproject · tor · CWE-290 | Yüksek7,5 | — | %2,7 | 29 Haz 2021 |
31İzleyin | CVE-2018-0490İstismar yok | An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.torproject · tor · CWE-476 | Yüksek7,5 | — | %2,6 | 5 Mar 2018 |
31İzleyin | CVE-2017-0375İstismar yok | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_ftorproject · tor · CWE-617 | Yüksek7,5 | — | %2,6 | 9 Haz 2017 |
31İzleyin | CVE-2017-0377İstismar yok | Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allowtorproject · tor · CWE-200 | Yüksek7,5 | — | %2,4 | 2 Tem 2017 |
31İzleyin | CVE-2020-10593İstismar yok | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aktorproject · tor · CWE-401 | Yüksek7,5 | — | %2,3 | 23 Mar 2020 |
31İzleyin | CVE-2015-2689İstismar yok | Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, torproject · tor · CWE-20 | Yüksek7,5 | — | %2,2 | 24 Oca 2020 |
31İzleyin | CVE-2015-2688İstismar yok | buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layotorproject · tor · CWE-755 | Yüksek7,5 | — | %2,2 | 24 Oca 2020 |
31İzleyin | CVE-2017-0376İstismar yok | The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_procetorproject · tor · CWE-617 | Yüksek7,5 | — | %2,2 | 9 Haz 2017 |
31İzleyin | CVE-2016-8860İstismar yok | Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,torproject · tor · CWE-119 | Yüksek7,5 | — | %1,9 | 4 Oca 2017 |
31İzleyin | CVE-2021-38385İstismar yok | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatiotorproject · tor · CWE-617 | Yüksek7,5 | — | %1,7 | 30 Ağu 2021 |
31İzleyin | CVE-2021-28089İstismar yok | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.torproject · tor · CWE-400 | Yüksek7,5 | — | %1,7 | 19 Mar 2021 |
30İzleyin | CVE-2021-34549İstismar yok | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.torproject · tor · CWE-400 | Yüksek7,5 | — | %1,6 | 29 Haz 2021 |
30İzleyin | CVE-2021-34550İstismar yok | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.torproject · tor · CWE-119 | Yüksek7,5 | — | %1,6 | 29 Haz 2021 |
- CVE-2016-907986Hemen
A use-after-free vulnerability in SVG Animation has been discovered.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %87debian · debian linux11 Haz 2018
- CVE-2018-1698340Planlayın
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html
KritikCVSS 9,8İstismar yokEPSS %3noscript · noscript13 Eyl 2018
- CVE-2026-7764237İzleyin
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type
KritikCVSS 9,3İstismar yokEPSS %0torproject · tor20 Ağu 2026
- CVE-2026-4460336İzleyin
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
KritikCVSS 9,1İstismar yokEPSS %1torproject · tor7 May 2026
- CVE-2026-4459736İzleyin
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
KritikCVSS 9,1İstismar yokEPSS %1torproject · tor6 May 2026
- CVE-2026-7763836İzleyin
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersona
KritikCVSS 9,0İstismar yokEPSS %0torproject · tor20 Ağu 2026
- CVE-2018-049134İzleyin
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
YüksekCVSS 7,5Kavram kanıtıEPSS %15torproject · tor5 Mar 2018
- CVE-2026-7764132İzleyin
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.
YüksekCVSS 8,2İstismar yokEPSS %0torproject · tor20 Ağu 2026
- CVE-2026-7758432İzleyin
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams.
YüksekCVSS 8,2İstismar yokEPSS %0torproject · tor20 Ağu 2026
- CVE-2019-895531İzleyin
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against To
YüksekCVSS 7,5İstismar yokEPSS %5torproject · tor21 Şub 2019
- CVE-2020-1059231İzleyin
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption)
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor23 Mar 2020
- CVE-2016-125431İzleyin
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor5 Ara 2017
- CVE-2021-3454831İzleyin
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor29 Haz 2021
- CVE-2018-049031İzleyin
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor5 Mar 2018
- CVE-2017-037531İzleyin
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_f
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor9 Haz 2017
- CVE-2017-037731İzleyin
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor2 Tem 2017
- CVE-2020-1059331İzleyin
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), ak
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor23 Mar 2020
- CVE-2015-268931İzleyin
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load,
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor24 Oca 2020
- CVE-2015-268831İzleyin
buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layo
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor24 Oca 2020
- CVE-2017-037631İzleyin
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_proce
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor9 Haz 2017
- CVE-2016-886031İzleyin
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination,
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor4 Oca 2017
- CVE-2021-3838531İzleyin
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verificatio
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor30 Ağu 2021
- CVE-2021-2808931İzleyin
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor19 Mar 2021
- CVE-2021-3454930İzleyin
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005.
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor29 Haz 2021
- CVE-2021-3455030İzleyin
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006.
YüksekCVSS 7,5İstismar yokEPSS %2torproject · tor29 Haz 2021