Vulnerabilities > TOR

DATE CVE VULNERABILITY TITLE RISK
2011-06-14 CVE-2011-1924 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in TOR
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
network
low complexity
tor CWE-119
5.0
2011-01-19 CVE-2011-0493 Numeric Errors vulnerability in TOR
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
network
low complexity
tor CWE-189
5.0
2011-01-19 CVE-2011-0492 Resource Management Errors vulnerability in TOR
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that trigger a certain file size, as demonstrated by the cached-descriptors.new file.
network
low complexity
tor CWE-399
5.0
2011-01-19 CVE-2011-0491 Improper Input Validation vulnerability in TOR
The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors, related to "underflow errors."
network
low complexity
tor CWE-20
5.0
2011-01-19 CVE-2011-0490 Denial of Service vulnerability in Tor
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denial of service (daemon crash) via vectors that trigger certain log messages.
network
low complexity
tor
5.0
2011-01-19 CVE-2011-0427 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in TOR
Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
network
tor CWE-119
6.8
2011-01-19 CVE-2011-0016 Resource Management Errors vulnerability in TOR
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.
local
low complexity
tor CWE-399
2.1
2011-01-19 CVE-2011-0015 Improper Input Validation vulnerability in TOR
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.
network
low complexity
tor CWE-20
5.0
2010-12-22 CVE-2010-1676 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in TOR
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
network
low complexity
tor CWE-119
critical
10.0
2010-01-25 CVE-2010-0385 Information Exposure vulnerability in TOR
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
network
low complexity
tor CWE-200
5.0