Where
-Infinity
0

Vendor Risk Score

See how torproject compares to other vendors in security performance

View Risk Score →

Tor Project TorTor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-…

Risk 66
Severity
9.1
First published (updated )

Tor Project TorNull Pointer Dereference

Risk 43
Severity
7.5
First published (updated )

Tor Project TorTor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because…

Risk 43
Severity
7.5
First published (updated )

Tor Project TorTor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a …

Risk 27
Severity
5.3
First published (updated )

Tor Project TorTor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tor Project TorTor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a re…

Risk 66
Severity
9.1
First published (updated )

Debian Debian LinuxThe SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol ca…

Risk 40
Severity
6.5
First published (updated )

torproject TorTor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

Risk 45
Severity
7.5
First published (updated )

torproject TorTor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allo…

Risk 32
Severity
5.5
First published (updated )

torproject Tor BrowserTor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise t…

Risk 46
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

torproject TorTor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verif…

Risk 43
Severity
7.5
First published (updated )

torproject TorBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

torproject TorAn issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain…

Risk 43
Severity
7.5
First published (updated )

torproject TorAn issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END o…

Risk 43
Severity
7.5
First published (updated )

torproject TorTor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an asser…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

torproject TorTor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resource…

Risk 43
Severity
7.5
First published (updated )

torproject TorTor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash)…

Risk 43
Severity
7.5
First published (updated )

torproject TorTor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau…

Risk 43
Severity
7.5
First published (updated )

torproject TorTor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau…

Risk 44
Severity
7.8
First published (updated )

torproject TorThe daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

torproject Torbuf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected ar…

Risk 43
Severity
7.5
First published (updated )

torproject TorInput Validation

Risk 43
Severity
7.5
First published (updated )

torproject TorThe Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0…

Risk 43
Severity
7.5
First published (updated )

torproject TorThe Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0…

Risk 43
Severity
7.5
First published (updated )

torproject Tor BrowserInfoleak

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

torproject Tor BrowserTor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to de…

Risk 22
Severity
4.3
First published (updated )

torproject TorIn Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-al…

Risk 43
Severity
7.5
First published (updated )

torproject Tor BrowserInfoleak

Risk 22
Severity
4.3
First published (updated )

NoScript NoScriptNoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to …

Risk 86
Severity
9.8
First published (updated )

torproject TorNull Pointer Dereference

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203