Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2012-3517 Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors rel… Tor after 0.2.2.37 Fix from $1,6002012-08-26 MEDIUM 5.0 CVE-2012-3518 The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allo… Tor after 0.2.2.37 Fix from $1,6002012-08-26 MEDIUM 5.0 CVE-2012-3519 routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow re… Tor after 0.2.2.37 Fix from $1,6002012-08-26 HIGH 7.6 CVE-2011-2778 Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execu… Tor after 0.2.2.34 Fix from $1,9502011-12-23 MEDIUM 5.8 CVE-2011-2768 Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote r… Tor after 0.2.2.33 Fix from $1,6002011-12-23 MEDIUM 5.0 CVE-2011-1924 Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (direct… Tor after 0.2.1.29 Fix from $1,6002011-06-14 MEDIUM 5.0 CVE-2011-0493 Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) v… Tor after 0.2.1.28 Fix from $1,6002011-01-19 MEDIUM 5.0 CVE-2011-0491 The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, wh… Tor after 0.2.1.28 Fix from $1,6002011-01-19 MEDIUM 5.0 CVE-2011-0492 Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via bl… Tor after 0.2.1.28 Fix from $1,6002011-01-19 MEDIUM 6.8 CVE-2011-0427 Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corr… Tor after 0.2.1.28 Fix from $1,6002011-01-19 MEDIUM 5.0 CVE-2011-0490 Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cau… Tor after 0.2.1.28 Fix from $1,6002011-01-19 MEDIUM 5.0 CVE-2011-0015 Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote … Tor after 0.2.1.28 Fix from $1,6002011-01-19 HIGH 10.0 CVE-2010-1676EPSS 8% Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon cras… Tor after 0.2.1.1.27 Fix from $1,9502010-12-22 MEDIUM 5.0 CVE-2010-0383 Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man… Tor Mitigation only Fix from $1,6002010-01-25 MEDIUM 5.0 CVE-2010-0385 Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive … Tor Mitigation only Fix from $1,6002010-01-25 MEDIUM 5.0 CVE-2009-2425 Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor. Tor Patch available Fix from $1,6002009-07-10 MEDIUM 5.0 CVE-2009-2426 The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit rel… Tor Patch available Fix from $1,6002009-07-10 HIGH 10.0 CVE-2009-0939 Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstr… Tor after 0.2.0.33 Fix from $1,9502009-03-18 MEDIUM 5.0 CVE-2009-0936 Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes." Tor after 0.2.0.33 Fix from $1,6002009-03-18 MEDIUM 5.0 CVE-2009-0937 Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors. Tor after 0.2.0.33 Fix from $1,6002009-03-18 MEDIUM 5.0 CVE-2009-0938 Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input." Tor after 0.2.0.33 Fix from $1,6002009-03-18 MEDIUM 5.1 CVE-2009-0654 Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sende… Tor after 0.2.0.34 Fix from $1,6002009-02-20 HIGH 10.0 CVE-2009-0414 Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption. Tor after 0.2.0.32 Fix from $1,9502009-02-03 HIGH 9.3 CVE-2008-5398 Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a po… Tor after 0.1.2.31 Fix from $1,9502008-12-09 HIGH 7.2 CVE-2008-5397 Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by l… Tor after 0.1.2.31 Fix from $1,9502008-12-09 MEDIUM 5.8 CVE-2007-4174EPSS 6% Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify… Tor after 0.1.2.15 Fix from $1,6002007-08-07 MEDIUM 6.4 CVE-2007-4097 Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive informa… Tor Patch available Fix from $1,6002007-07-30 MEDIUM 5.8 CVE-2007-4096 Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors. Tor Patch available Fix from $1,6002007-07-30 MEDIUM 5.8 CVE-2007-4098 Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers … Tor Patch available Fix from $1,6002007-07-30 MEDIUM 5.8 CVE-2007-4099 Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control … Tor Patch available Fix from $1,6002007-07-30