CVE-2017-16541
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
- Torproject Tor
- < 7.0.9
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 3.7% (89th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-11-04
CVE-2017-16541 at NVD
4 known exploits for CVE-2017-16541
Proof-of-concept code and exploit modules indexed by Sploitus