Products: 1
    Vulnerabilities: 58
    Known Exploited: 0
    4
    Critical Level Threats
    3
    High Level Threats
    48
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-4444

    Tor Onion Service Descriptor resource consumption

    Last Modified: Apr 15, 2026
    Published: Sep 18, 2025

    CVE-2012-3519

    routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-channel attack.

    Last Modified: Apr 11, 2025
    Published: Aug 26, 2012

    CVE-2012-3518

    The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.

    Last Modified: Apr 11, 2025
    Published: Aug 26, 2012

    CVE-2012-3517

    Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.

    Last Modified: Apr 11, 2025
    Published: Aug 26, 2012

    CVE-2011-4896

    Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.

    Last Modified: Apr 11, 2025
    Published: Dec 23, 2011
    Items Per Page
    Tor Vulnerabilities & Security CVEs | CVE-DB