📦

tor

Vendor: debian

Actively Exploited 1 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 2 Remote Access
Total CVEs 17 Total Indexed
Avg. EPSS 2.14% Exploit Prob.
Latest CVE CVE-2026-44603 May 07

Security Vulnerability Index

Page 1 / 2
3.7 CVSS

Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.

EPSS: 0.06%
3.7 CVSS

Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.

EPSS: 0.05%
3.7 CVSS

Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.

EPSS: 0.05%
3.7 CVSS

Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.

EPSS: 0.02%
3.7 CVSS

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

EPSS: 0.01%
3.7 CVSS

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

EPSS: 0.02%
6.5 CVSS

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

EPSS: 0.78%
7.5 CVSS

Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

EPSS: 0.64%
5.5 CVSS

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.

EPSS: 0.12%
7.5 CVSS

Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

EPSS: 0.60%