{"id":"ECHO-21a6-33d6-5465","summary":"Tor Browser information exposure vulnerability. This CVE is for Tor Browser,\nnot Firefox ESR. Tracked against firefox-esr only because Tor Browser is based\non Firefox, but the vulnerability is in Tor-specific code not present in firefox-esr.\nhttps://security-tracker.debian.org/tracker/CVE-2019-12383\n","modified":"2026-09-15T03:33:36.213953010Z","published":"2026-05-13T18:23:56.141207Z","withdrawn":"2026-03-17T12:30:04.167Z","upstream":["CVE-2019-12383"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2019-12383"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12383"},{"type":"WEB","url":"http://www.securityfocus.com/bid/108484"},{"type":"WEB","url":"https://gitweb.torproject.org/tor-browser.git/commit/?id=cbb04b72c68272c2de42f157d40cd7d29a6b7b55"},{"type":"WEB","url":"https://hackerone.com/reports/282748"},{"type":"WEB","url":"https://trac.torproject.org/projects/tor/ticket/24056"},{"type":"WEB","url":"http://www.securityfocus.com/bid/108484"},{"type":"WEB","url":"https://gitweb.torproject.org/tor-browser.git/commit/?id=cbb04b72c68272c2de42f157d40cd7d29a6b7b55"},{"type":"WEB","url":"https://hackerone.com/reports/282748"},{"type":"WEB","url":"https://trac.torproject.org/projects/tor/ticket/24056"}],"affected":[{"package":{"name":"firefox-esr","ecosystem":"Echo","purl":"pkg:deb/echo/firefox-esr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.8.0esr-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-21a6-33d6-5465.json"}}],"schema_version":"1.9.0"}