Toktok's vulnerability footprint centers on ToxCore, a decentralized peer-to-peer communications library, with the observed weakness classes centered on information disclosure, improper resource management, and calculation errors typical of low-level networking and cryptographic code. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toktok over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44847CRITICAL A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the hand | Dec 13, 2021 | 9.8 | 33 | NO | NO |
CVE-2018-25021HIGH The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a | Dec 13, 2021 | 7.5 | 26 | NO | NO |
The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing onl | Dec 13, 2021 | 3.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toktok.
Media articles that mention a CVE ID that affects a product developed by Toktok — matched by CVE ID, not by vendor name.