Skip to main content

Vendor/product archive

mozilla / network_security_services CVEs

Beta · best-effort

50 CVEs tagged to mozilla / network_security_services6 Critical, 19 High, 24 Medium, 1 Low, 0 Unrated.

CVE-2022-3479

Published Oct 14, 2022

A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or cras…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12404

Published May 2, 2019

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12384

Published Apr 29, 2019

When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8635

Published Aug 1, 2018

It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private…

CVSS 5.3 · Medium

CVE-2017-11698

Published Dec 27, 2017

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified imp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11697

Published Dec 27, 2017

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and cra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11696

Published Dec 27, 2017

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11695

Published Dec 27, 2017

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7502

Published May 30, 2017

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5461

Published May 11, 2017

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denia…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2834

Published Jun 13, 2016

Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and applicatio…

CVSS 8.8 · High

CVE-2016-1979

Published Mar 13, 2016

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 4…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1950

Published Mar 13, 2016

Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 3…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2015-2730

Published Jul 6, 2015

Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not prop…

CVSS 4.3 · Medium
Showing 1-25 of 50 CVEsPage 1 of 2