CVE-2006-3127
published 2006-06-21CVE-2006-3127: Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows…
PriorityP427high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.10%
86.2th percentile
Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_enterprise_system | — | — |
| sun | java_enterprise_system | — | — |
| sun | java_enterprise_system | — | — |
| sun | java_system_directory_server | — | — |
| sun | java_system_web_server | — | — |
| sun | one_application_server | <= 7.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jc9w-4vh5-cjvm: Memory leak in Network Security Services (NSS) 3
ghsa_unreviewed·2022-05-01
CVE-2006-3127 [HIGH] GHSA-jc9w-4vh5-cjvm: Memory leak in Network Security Services (NSS) 3
Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.
GHSA
GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2006-5654 [HIGH] GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/25048http://securitytracker.com/id?1016294http://sunsolve.sun.com/search/document.do?assetkey=1-26-102461-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102896-1http://www.redhat.com/archives/fedora-package-announce/2006-June/msg00155.htmlhttp://www.securityfocus.com/bid/18604http://www.securityfocus.com/bid/20846http://www.vupen.com/english/advisories/2007/1573http://secunia.com/advisories/25048http://securitytracker.com/id?1016294http://sunsolve.sun.com/search/document.do?assetkey=1-26-102461-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102896-1http://www.redhat.com/archives/fedora-package-announce/2006-June/msg00155.htmlhttp://www.securityfocus.com/bid/18604http://www.securityfocus.com/bid/20846http://www.vupen.com/english/advisories/2007/1573
2006-06-21
Published