CVE-2015-2689
CVE-2015-2689 is a high-severity vulnerability in Torproject Tor with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 2% (82nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Torproject Tor
- Published:
- Last modified:
Description
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Frequently asked questions
- What is CVE-2015-2689?
- Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
- How severe is CVE-2015-2689?
- CVE-2015-2689 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2015-2689 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (82nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-2689?
- CVE-2015-2689 affects Torproject Tor. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2015-2689?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2015-2689 published?
- CVE-2015-2689 was published on 2020-01-24 and last updated on 2026-06-17.
References
- https://lists.torproject.org/pipermail/tor-talk/2015-March/037281.html
- https://trac.torproject.org/projects/tor/ticket/14129
Affected products (1)
- cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
More vulnerabilities in Torproject Tor
- CVE-2026-77638 — High (CVSS 8.9): Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could…
- CVE-2026-77642 — High (CVSS 7.5): tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected…
- CVE-2022-33903 — High (CVSS 7.5): Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
- CVE-2021-38385 — High (CVSS 7.5): Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and…
- CVE-2021-34550 — High (CVSS 7.5): An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows…
- CVE-2021-34549 — High (CVSS 7.5): An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of…
All CVEs affecting Torproject Tor →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →