CVE-2020-15572: Torproject Tor

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

Affected products

  • Torproject Tor: before 0.3.5.11 (fixed in 0.3.5.11); after 0.4.2.0, before 0.4.2.8 (fixed in 0.4.2.8); after 0.4.3.0, before 0.4.3.6 (fixed in 0.4.3.6); version 0.4.4.0 only; version 0.4.4.1 only

Published 2020-07-15. Last modified 2026-06-17.