Vulnerabilities > Torproject > TOR

DATE CVE VULNERABILITY TITLE RISK
2020-03-23 CVE-2020-10593 Memory Leak vulnerability in multiple products
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004.
network
low complexity
torproject opensuse CWE-401
7.5
2020-03-23 CVE-2020-10592 Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
network
low complexity
torproject opensuse
7.5
2020-02-02 CVE-2020-8516 Unspecified vulnerability in Torproject TOR
The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information.
network
low complexity
torproject
5.3
2020-01-24 CVE-2015-2929 Unspecified vulnerability in Torproject TOR
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
network
low complexity
torproject
7.5
2020-01-24 CVE-2015-2928 Unspecified vulnerability in Torproject TOR
The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
network
low complexity
torproject
7.5
2020-01-24 CVE-2015-2689 Improper Input Validation vulnerability in Torproject TOR
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
network
low complexity
torproject CWE-20
7.5
2020-01-24 CVE-2015-2688 Improper Handling of Exceptional Conditions vulnerability in Torproject TOR
buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
network
low complexity
torproject CWE-755
7.5
2019-02-21 CVE-2019-8955 Allocation of Resources Without Limits or Throttling vulnerability in Torproject TOR
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
network
low complexity
torproject CWE-770
7.5
2018-06-11 CVE-2016-9079 Use After Free vulnerability in multiple products
A use-after-free vulnerability in SVG Animation has been discovered.
network
low complexity
debian redhat mozilla torproject CWE-416
7.5
2018-03-05 CVE-2018-0491 Use After Free vulnerability in Torproject TOR
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
network
low complexity
torproject CWE-416
7.5