Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DAC8510-95BF-4FF8-9975-86AA5A0417C5", "versionEndExcluding": "0.3.5.11", "vulnerable": true}, {"criteria": "cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*", "matchCriteriaId": "95D2A6D5-E281-4514-A4BC-74736E93BECD", "versionEndExcluding": "0.4.2.8", "versionStartExcluding": "0.4.2.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*", "matchCriteriaId": "04AC62C8-A529-439A-8D7D-C79EA9658F76", "versionEndExcluding": "0.4.3.6", "versionStartExcluding": "0.4.3.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:torproject:tor:0.4.4.0:alpha:*:*:*:*:*:*", "matchCriteriaId": "C3708B4D-8F02-47B4-81E8-AA626B04C906", "vulnerable": true}, {"criteria": "cpe:2.3:a:torproject:tor:0.4.4.1:alpha:*:*:*:*:*:*", "matchCriteriaId": "2143F2C0-BBD4-4B14-84D6-70125DD37376", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001."}, {"lang": "es", "value": "Tor versiones anteriores a 0.4.3.6, presenta un acceso de la memoria fuera de l\u00edmites que permite un ataque de denegaci\u00f3n de servicio remoto (bloqueo) contra instancias de Tor creadas para usar Mozilla Network Security Services (NSS), tambi\u00e9n se conoce como TROVE-2020-001"}], "id": "CVE-2020-15572", "lastModified": "2024-11-21T05:05:46.193", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2020-07-15T17:15:11.283", "references": [{"source": "cve@mitre.org", "tags": ["Release Notes", "Vendor Advisory"], "url": "https://blog.torproject.org/new-release-tor-03511-0428-0436-security-fixes"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "https://gitlab.torproject.org/tpo/core/tor/-/issues/33119"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "https://trac.torproject.org/projects/tor/wiki/TROVE"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes", "Vendor Advisory"], "url": "https://blog.torproject.org/new-release-tor-03511-0428-0436-security-fixes"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://gitlab.torproject.org/tpo/core/tor/-/issues/33119"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://trac.torproject.org/projects/tor/wiki/TROVE"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-125"}], "source": "nvd@nist.gov", "type": "Primary"}]}