CVE-2019-13075
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
- Affected products
- Firefox, Tor Browser
- Torproject Tor Browser
- ≤ 8.5.3
- Fix
- Available
- CVSS 3.0
- 5.3 MEDIUM
- EPSS
- 1.9% (77th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2019-06-30
CVE-2019-13075 at NVD
No indexed exploits for CVE-2019-13075 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-13075 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.