9.3
CVE-2026-77642
- EPSS -
- Veröffentlicht 20.08.2026 21:15:49
- Zuletzt bearbeitet 08.09.2026 18:11:10
- Erkennungen
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Torproject ≫ Tor Version < 0.4.9.9
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
|
| MITRE | 7.5 | 2.2 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog