CVE-2013-5605Improper Input Validation in Mozilla Network Security Services

Severity
7.5HIGHNVD
EPSS
2.8%
top 13.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 14

Description

Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianmozilla/nss< 2:3.15.3-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mv87-4w29-5g7x: Mozilla Network Security Services (NSS) 32022-05-14
OSV
CVE-2013-5605: Mozilla Network Security Services (NSS) 32013-11-18
CVEList
CVE-2013-5605: Mozilla Network Security Services (NSS) 32013-11-16

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2013-11-21
Ubuntu
Firefox vulnerabilities2013-11-20
Ubuntu
NSS vulnerabilities2013-11-18
Red Hat
nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)2013-11-13
Debian
CVE-2013-5605: nss - Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15....2013

💬Community

2
Bugzilla
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]2013-11-19
Bugzilla
CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)2013-11-15
CVE-2013-5605 — Improper Input Validation in Mozilla | cvebase