ZeroHour

Vulnerabilities

42 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-77642
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type.

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

NVD description · AI analysis pending
9.3
group max
<1%
  • torproject tor
CVE-2026-44597
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

NVD description · AI analysis pending
9.1
group max
<1%
  • torproject tor
CVE-2023-23589
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

NVD description · AI analysis pending
6.5<1% PoC
  • torproject tor
  • torproject debian linux
  • torproject fedora
CVE-2022-33903
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

NVD description · AI analysis pending
7.51%
  • torproject tor
CVE-2021-46702
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure.

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.

NVD description · AI analysis pending
5.5<1%
  • torproject tor
CVE-2021-39246
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses.

Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network).

NVD description · AI analysis pending
6.1<1% PoC ×2
  • torproject tor browser
CVE-2021-38385
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remo

Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

NVD description · AI analysis pending
7.52% PoC
  • torproject tor
CVE-2021-34548
+2 in the same advisory: …34549 …34550
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

NVD description · AI analysis pending
7.53%
  • torproject tor
CVE-2021-28089
+1 in the same advisory: …28090
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

NVD description · AI analysis pending
7.5
group max
2%
  • torproject tor
  • torproject fedora
CVE-2020-15572
Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network S

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

NVD description · AI analysis pending
7.51%
  • torproject tor
CVE-2020-10592
+1 in the same advisory: …10593
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.

NVD description · AI analysis pending
7.53%
  • torproject tor
  • torproject backports
  • torproject leap
CVE-2020-8516
The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might ma

The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability

NVD description · AI analysis pending
5.32% PoC
  • torproject tor
CVE-2019-13075
Tor Browser through 8.5.3 has an information exposure vulnerability.

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

NVD description · AI analysis pending
5.32% PoC
  • torproject tor browser
CVE-2019-12383
Tor Browser before 8.0.1 has an information exposure vulnerability.

Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.

NVD description · AI analysis pending
4.32%
  • torproject tor browser
CVE-2019-8955
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays

In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.

NVD description · AI analysis pending
7.55%
  • torproject tor
CVE-2017-16639
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability t

Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.

NVD description · AI analysis pending
4.32% PoC ×3
  • torproject tor browser
CVE-2018-16983
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type

NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.

NVD description · AI analysis pending
9.83%
  • noscript noscript
  • noscript tor browser
CVE-2016-9079
Use-After-Free in Mozilla Firefox and Tor Browser SVG Animation Exploited in the Wild

CVE-2016-9079 is a use-after-free flaw (CWE-416) in the SVG Animation component of Mozilla's Gecko engine, affecting Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1, as well as the Firefox-ESR-based Tor Browser and distro-packaged builds on Debian and Red Hat Enterprise Linux. It is triggered when the browser renders SVG content with animations, typically by loading a crafted web page, causing a freed SVG animation object to be reused and corrupting memory. A successful attack can lead to arbitrary code execution in the browser context or disclosure of sensitive memory contents; the assigned CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network-triggered memory corruption with high confidentiality impact and no privileges required. The in-the-wild exploit observed at disclosure targeted Firefox and Tor Browser users on Windows. The flaw has public PoC exploits, carries an EPSS 30-day exploitation probability of 87.4% (100th percentile), and was added to the CISA KEV catalog on 2023-06-22 with a required action to apply vendor updates.

Do: Upgrade Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later, and install the corresponding patched Tor Browser build; users on Windows were the observed in-the-wild targets, so prioritize those hosts. On Debian and Red Hat Enterprise Linux, apply the vendor's updated firefox/thunderbird/tor packages per their advisories, consistent with the CISA KEV required action. As an interim mitigation, restrict loading of untrusted web content with animated SVG and verify no machines in the environment are still running Firefox versions older than 50.0.2.

7.587% KEV PoC ×3
  • mozilla Firefox < 50.0.2
  • mozilla Firefox ESR < 45.5.1
  • mozilla Thunderbird < 45.5.1
  • +3 more
mass~200-300 million Firefox users/install base at the time of disclosure (late 2016), plus roughly 1-2 million Tor Browser daily users (Windows-targeted…
CVE-2018-0491
+1 in the same advisory: …0490
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.

A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.

NVD description · AI analysis pending
7.515% PoC
  • torproject tor
CVE-2016-1254
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

NVD description · AI analysis pending
7.53%
  • torproject tor
  • torproject debian linux
  • torproject fedora
  • +1 more
CVE-2017-16541
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involv

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.

NVD description · AI analysis pending
6.54% PoC
  • torproject tor
  • torproject enterprise linux desktop
  • torproject enterprise linux eus
  • +1 more
CVE-2017-0380
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7

The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.

NVD description · AI analysis pending
5.92%
  • torproject tor
CVE-2017-0377
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to

Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.

NVD description · AI analysis pending
7.52%
  • torproject tor
CVE-2017-0375
+1 in the same advisory: …0376
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function v

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

NVD description · AI analysis pending
7.53%
  • torproject tor
CVE-2016-8860
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination, but the implementat

Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination, but the implementation of or/buffers.c did not ensure that NUL termination was present, which allows remote attackers to cause a denial of service (client, hidden service, relay, or authority crash) via crafted data.

NVD description · AI analysis pending
7.52%
  • torproject tor