VDB

CVE-2017-16541

CVE-2017-16541 PUBLISHED

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.

EPSS 7.69% · 92.0th percentile

Risk Scores

EPSS Score
7.69%
92.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSthunderbird0, *, 1:52.8.0+build1-0ubuntu0.18.04.1
Ubuntu:16.04:LTSthunderbird1:45.3.0+build1-0ubuntu0.16.04.2, 1:45.4.0+build1-0ubuntu0.16.04.1, 1:45.7.0+build1-0ubuntu0.16.04.1
Ubuntu:18.04:LTSfirefox0, 56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1
Ubuntu:16.04:LTSfirefox55.0.1+build2-0ubuntu0.16.04.2, 55.0.2+build1-0ubuntu0.16.04.1, 56.0+build6-0ubuntu0.16.04.1

Timeline

  • Nov 4, 2017 CVE Published
  • Sep 11, 2018 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›