6.5
CVSSv3

CVE-2017-16541

Published: 04/11/2017 Updated: 18/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Tor Browser prior to 7.0.9 on macOS and Linux allows remote malicious users to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

torproject tor

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux eus 7.5

redhat enterprise linux eus 7.6

redhat enterprise linux eus 7.7

redhat enterprise linux server 6.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.6

redhat enterprise linux server aus 7.7

redhat enterprise linux server tus 7.6

redhat enterprise linux server tus 7.7

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Mozilla Foundation Security Advisory 2018-21 Security vulnerabilities fixed in Firefox ESR 602 Announced September 5, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 602 ...
Mozilla Foundation Security Advisory 2018-20 Security vulnerabilities fixed in Firefox 62 Announced September 5, 2018 Impact critical Products Firefox Fixed in Firefox 62 ...
Mozilla Foundation Security Advisory 2018-25 Security vulnerabilities fixed in Thunderbird 6021 Announced October 4, 2018 Impact critical Products Thunderbird Fixed in Thunderbird 6021 ...

Exploits

This write up holds the details for the Tor Browser information disclosure vulnerability as discussed in CVE-2017-16541 Version 708 is affected ...
Tor Browser versions prior to 80 are affected by an information disclosure vulnerability that allows remote attackers to bypass the intended anonymity feature and discover a client IP address The vulnerability affects Windows users only and needs user interaction to be exploited ...

Github Repositories