Tor

Vendor:

First CVE: Jun 28, 2005 · Active for 21 years

103
Total CVEs
More Total CVEs than 97% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 36% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Tor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2005
21 years ago
Most Recent CVE
May 7, 2026
78 days ago

CVE Severity & Scoring

Tor103 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network38 (36.9%)
Unknown64 (62.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (35.0%)
High3 (2.9%)
Unknown64 (62.1%)
User Interaction
None38 (36.9%)
Unknown64 (62.1%)
Required1 (1.0%)
Privileges Required
Low1 (1.0%)
High0 (0.0%)
None38 (36.9%)
Unknown64 (62.1%)

Top CVEs

Signals from CVEs in this product scope (103 CVEs).

103 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users
Jun 11, 20187.597YESYES
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a
Mar 5, 20187.542NOYES
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
May 7, 20269.134NONO
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar
Dec 22, 201010.033NONO
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
May 7, 20269.132NONO
Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
May 7, 20267.528NONO
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.
May 7, 20267.528NONO
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
Mar 23, 20207.526NONO
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memor
Feb 21, 20197.526NONO
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 d
Dec 3, 20178.126NONO

Exploit Exposure

Signals from CVEs in this product scope (103 CVEs).

CISA KEV
1 CVE
1.0% of CVEs· 96th percentile
Metasploit
1 CVE
1.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
2.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (103 CVEs).

Media Mentions

Signals from CVEs in this product scope (103 CVEs).

Top CNAs Publishing CVEs For Tor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.715.50.4%00
0.4.4.326.41.9%00
0.4.4.226.41.9%00
0.4.4.136.81.7%00
0.4.4.036.81.7%00
0.4.0.117.54.6%00
0.3.5.717.54.6%00
0.3.5.617.54.6%00
0.3.5.517.54.6%00
0.3.5.417.54.6%00
0.3.5.317.54.6%00
0.3.5.217.54.6%00
0.3.5.117.54.6%00
0.3.5.017.54.6%00
0.3.4.717.54.6%00
0.3.4.617.54.6%00
0.3.4.517.54.6%00
0.3.4.417.54.6%00
0.3.4.317.54.6%00
0.3.4.217.54.6%00