CVE-2014-1491
published 2014-02-06CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
4.66%
90.8th percentile
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nss | < nss 2:3.15.4-1 (bookworm) | nss 2:3.15.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 2.6.34 < 5.10.248 | 5.10.248 |
| linux | linux_kernel | >= 5.11.0 < 5.15.198 | 5.15.198 |
| linux | linux_kernel | >= 5.16.0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.13.0 < 6.17.13 | 6.17.13 |
| linux | linux_kernel | >= 6.18.0 < 6.18.2 | 6.18.2 |
| linux | linux_kernel | >= 6.2.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.12.63 | 6.12.63 |
| mozilla | firefox | < 24.3 | 24.3 |
| mozilla | firefox | < 27.0 | 27.0 |
| mozilla | network_security_services | < 3.15.4 | 3.15.4 |
| mozilla | nss | >= 0 < 2:3.15.4-1 | 2:3.15.4-1 |
| mozilla | nss | >= 0 < 2:3.15.4-1 | 2:3.15.4-1 |
| mozilla | nss | >= 0 < 2:3.15.4-1 | 2:3.15.4-1 |
| mozilla | nss | >= 0 < 2:3.15.4-1 | 2:3.15.4-1 |
| mozilla | seamonkey | < 2.24 | 2.24 |
| mozilla | thunderbird | < 24.3.0 | 24.3.0 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu9.8CRITICAL
vendor_redhat5.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
vendor_redhat·2025-12-24·CVSS 5.3
CVE-2025-68367 [MEDIUM] CWE-366 kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
In the Linux kernel, the following vulnerability has been resolved:
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
The following warning appears when running syzkaller, and this issue also
exists in the mainline code.
------------[ cut here ]------------
list_add double add: new=ffffffffa57eee28, prev=ffffffffa57eee28, next=ffffffffa5e63100.
WARNING: CPU: 0 PID: 1491 at lib/list_debug.c:35 __list_add_valid_or_report+0xf7/0x130
Modules linked in:
CPU: 0 PID: 1491 Comm: syz.1.28 Not tainted 6.6.0+ #3
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:__list_add_valid_or_report+0xf7/0x130
RSP: 00
Ubuntu
Firefox regression
vendor_ubuntu·2014-02-19·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-2102-1 introduced a regression in Firefox.
USN-2102-1 fixed vulnerabilities in Firefox. The update introduced a
regression which could make Firefox crash under some circumstances. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric
Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Carsten Book,
Andrew Sutherland, Byron Campen, Nicholas Nethercote, Paul Adenot, David
Baron, Julian Seward and Sotaro Ikeda discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-02-19·CVSS 9.8
CVE-2014-1477 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric
Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen and Sotaro Ikeda
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message with scripting enabled,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Thunderbird. (CVE-2014-1477)
Cody Crews discovered a method to bypass System Only Wrappers. If a user
had enabled scripting, an attacker could potentially exploit this to steal
confidential data or execute code with the privileges of the user invoking
Thun
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-02-10·CVSS 9.8
CVE-2014-1477 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric
Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Carsten Book,
Andrew Sutherland, Byron Campen, Nicholas Nethercote, Paul Adenot, David
Baron, Julian Seward and Sotaro Ikeda discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1477,
CVE-2014-1478)
Cody Crews discovered a method to bypass System Only Wrappers. An attacker
could potentially e
Red Hat
nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
vendor_redhat·2014-02-04·CVSS 4.3
CVE-2014-1491 [MEDIUM] CWE-358 nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE) parameters. This could possibly lead to weak encryption being used in communication between the client and the server.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-1491: nss - Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefo...
vendor_debian·2014·CVSS 4.3
CVE-2014-1491 [MEDIUM] CVE-2014-1491: nss - Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefo...
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
Scope: local
bookworm: resolved (fixed in 2:3.15.4-1)
bullseye: resolved (fixed in 2:3.15.4-1)
forky: resolved (fixed in 2:3.15.4-1)
sid: resolved (fixed in 2:3.15.4-1)
trixie: resolved (fixed in 2:3.15.4-1)
OSV
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
osv·2025-12-24
CVE-2025-68367 macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
In the Linux kernel, the following vulnerability has been resolved:
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
The following warning appears when running syzkaller, and this issue also
exists in the mainline code.
------------[ cut here ]------------
list_add double add: new=ffffffffa57eee28, prev=ffffffffa57eee28, next=ffffffffa5e63100.
WARNING: CPU: 0 PID: 1491 at lib/list_debug.c:35 __list_add_valid_or_report+0xf7/0x130
Modules linked in:
CPU: 0 PID: 1491 Comm: syz.1.28 Not tainted 6.6.0+ #3
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:__list_add_valid_or_report+0xf7/0x130
RSP: 0018:ff1100010dfb7b78 EFLAGS: 00010282
R
GHSA
GHSA-v496-3mj8-fpc6: Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-13
CVE-2014-1491 [MEDIUM] CWE-326 GHSA-v496-3mj8-fpc6: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
OSV
CVE-2014-1491: Mozilla Network Security Services (NSS) before 3
osv·2014-02-06·CVSS 4.3
CVE-2014-1491 [MEDIUM] CVE-2014-1491: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-68367 kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
bugzilla·2025-12-24
CVE-2025-68367 [MEDIUM] CVE-2025-68367 kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
CVE-2025-68367 kernel: Linux kernel (macintosh/mac_hid): Denial of Service via race condition in mac_hid_toggle_emumouse
In the Linux kernel, the following vulnerability has been resolved:
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
The following warning appears when running syzkaller, and this issue also
exists in the mainline code.
------------[ cut here ]------------
list_add double add: new=ffffffffa57eee28, prev=ffffffffa57eee28, next=ffffffffa5e63100.
WARNING: CPU: 0 PID: 1491 at lib/list_debug.c:35 __list_add_valid_or_report+0xf7/0x130
Modules linked in:
CPU: 0 PID: 1491 Comm: syz.1.28 Not tainted 6.6.0+ #3
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:__list_add_valid_or_report+
Bugzilla
Small subgroup attack
bugzilla·2015-04-30·CVSS 4.3
CVE-2014-1491 [MEDIUM] Small subgroup attack
Small subgroup attack
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:35.0) Gecko/20100101 Firefox/35.0
Build ID: 20150122214805
Steps to reproduce:
When using TLS_DHE_RSA_WITH_AES_128_CBC_SHA Chrome doesn't accept degenerate public key of value 0,1 and -1 since this key lead to pms that is {0,1, -1}.
This (the -1 case) is probably a consequence of CVE-2014-1491 (raised as part of the Triple Handshake Attack [0]).
I would refer to the classic Diffie Hellman nomenclature
* p as the prime number
* g the generator with order p-1 = q
* y public key
* x private key
Observation #1
If (p-1)/4 = 0 (mod p) then if I choose my private key x = (p-1)/4 then my public key
y = g^x will generates a prime-order subgroup of size 4.
This means that Chrome will agree on a pms = 1 one time
Bugzilla
CVE-2014-1491 nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
bugzilla·2014-02-04·CVSS 4.3
CVE-2014-1491 [MEDIUM] CVE-2014-1491 nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
CVE-2014-1491 nss: Do not allow p-1 as a public DH value (MFSA 2014-12)
1. Create a TLS server supporting only the DHE key exchange.
2. During any handshake, send the parameters where p=2q+1 is a prime such that q is also prime and g is not a quadratic residue mod p
3. NSS accepts this value and proceeds with the handshake. The PMS computed by NSS is g^(q*Kc)
Actual results:
NSS accepts to proceed with the exchange. If g is not a quadratic residue mod p, then g^q = p-1 which is not rejected by NSS as it accepts any public value in [2, p-1] (this is allowed by rfc2631). Then, the computed PMS g^(q*Kc) is 1 if Kc is even (because g^(2q)=g^(p-1)=1 [mod p]) and p-1 if Kc is odd (because g^q=p-1 [mod p]). If the server chose a Ks with the same parity, the PMS will be the same on the client
http://hg.mozilla.org/projects/nss/rev/12c42006aed8http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/56858http://secunia.com/advisories/56888http://secunia.com/advisories/56922http://www.debian.org/security/2014/dsa-2858http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2014/mfsa2014-12.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65332http://www.securitytracker.com/id/1029717http://www.securitytracker.com/id/1029720http://www.securitytracker.com/id/1029721http://www.ubuntu.com/usn/USN-2102-1http://www.ubuntu.com/usn/USN-2102-2http://www.ubuntu.com/usn/USN-2119-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=934545https://exchange.xforce.ibmcloud.com/vulnerabilities/90886https://security.gentoo.org/glsa/201504-01http://hg.mozilla.org/projects/nss/rev/12c42006aed8http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/56858http://secunia.com/advisories/56888http://secunia.com/advisories/56922http://www.debian.org/security/2014/dsa-2858http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2014/mfsa2014-12.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65332http://www.securitytracker.com/id/1029717http://www.securitytracker.com/id/1029720http://www.securitytracker.com/id/1029721http://www.ubuntu.com/usn/USN-2102-1http://www.ubuntu.com/usn/USN-2102-2http://www.ubuntu.com/usn/USN-2119-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=934545https://exchange.xforce.ibmcloud.com/vulnerabilities/90886https://security.gentoo.org/glsa/201504-01
2014-02-06
Published