CVE-2018-0491
HIGHTor 0.3.2.0-0.3.2.9 - Use-After-Free in KIST Pending List
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-0491. PoCs published by t4rkd3vilz.
AI-analyzed exploit summary This exploit leverages a Use After Free vulnerability in Tor Browser to trigger a Denial of Service (DoS) by manipulating DOM elements and event listeners. The PoC demonstrates the vulnerability by causing a crash through improper handling of frameset elements.
Description
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.
Exploits (1)
This exploit leverages a Use After Free vulnerability in Tor Browser to trigger a Denial of Service (DoS) by manipulating DOM elements and event listeners. The PoC demonstrates the vulnerability by causing a crash through improper handling of frameset elements.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H