Debian Nss vulnerabilities
74 known vulnerabilities affecting debian/nss.
Total CVEs
74
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH20MEDIUM33LOW12
Vulnerabilities
Page 1 of 4
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr...
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2016-0800P2MEDIUMCVSS 5.9PoCfixed in nss 3.13 (bookworm)2016
CVE-2016-0800 [MEDIUM] CVE-2016-0800: nss - The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and...
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
Scope:
debian
CVE-2015-4000P3LOWCVSS 3.7PoCfixed in nss 2:3.19.1-1 (bookworm)2015
CVE-2015-4000 [LOW] CVE-2015-4000: nss - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a ...
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" is
debian
CVE-2014-3566P3LOWCVSS 3.4PoCfixed in erlang 1:17.3-dfsg-3 (bookworm)2014
CVE-2014-3566 [LOW] CVE-2014-3566: bouncycastle - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses...
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2011-3389P3MEDIUMCVSS 4.3PoCfixed in asterisk 1:13.7.2~dfsg-1 (bullseye)2011
CVE-2011-3389 [MEDIUM] CVE-2011-3389: asterisk - The SSL protocol, as used in certain configurations in Microsoft Windows and Mic...
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS s
debian
CVE-2021-43527P2CRITICALCVSS 9.8fixed in nss 2:3.73-1 (bookworm)2021
CVE-2021-43527 [CRITICAL] CVE-2021-43527: nss - NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnera...
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL func
debian
CVE-2018-12404P3MEDIUMCVSS 5.9fixed in nss 2:3.41-1 (bookworm)2018
CVE-2018-12404 [MEDIUM] CVE-2018-12404: nss - A cached side channel attack during handshakes using RSA encryption could allow ...
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
Scope: local
bookworm: resolved (fixed in 2:3.41-1)
bullseye: resolved (fixed in 2:3.41-1)
forky: resolved (fixed
debian
CVE-2019-17006P3CRITICALCVSS 9.8fixed in nss 2:3.47-1 (bookworm)2019
CVE-2019-17006 [CRITICAL] CVE-2019-17006: nss - In Network Security Services (NSS) before 3.46, several cryptographic primitives...
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2:3.47-1)
bullseye: resolved (fixed in 2:3.47-1)
forky: resolved (fix
debian
CVE-2015-7182P3CRITICALCVSS 9.8fixed in nss 2:3.20.1-1 (bookworm)2015
CVE-2015-7182 [CRITICAL] CVE-2015-7182: nss - Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Serv...
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
Scope: local
b
debian
CVE-2017-5461P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5461 [CRITICAL] CVE-2017-5461: firefox - Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x bef...
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2016-1950P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2014-1544P3CRITICALCVSS 10.0fixed in nss 2:3.16.3-1 (bookworm)2014
CVE-2014-1544 [CRITICAL] CVE-2014-1544: nss - Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3....
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust doma
debian
CVE-2020-12403P3CRITICALCVSS 9.1fixed in nss 2:3.55-1 (bookworm)2020
CVE-2020-12403 [CRITICAL] CVE-2020-12403: nss - A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions...
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and
debian
CVE-2026-2781P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2781 [CRITICAL] CVE-2026-2781: firefox - Integer overflow in the Libraries component in NSS. This vulnerability affects F...
Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2024-6602P3CRITICALCVSS 9.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6602 [CRITICAL] CVE-2024-6602: firefox - A mismatch between allocator and deallocator could have led to memory corruption...
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2023-0767P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-0767 [HIGH] CVE-2023-0767: firefox - An attacker could construct a PKCS 12 cert bundle in such a way that could allow...
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2014-1568P3HIGHCVSS 7.5fixed in nss 2:3.17.1-1 (bookworm)2014
CVE-2014-1568 [HIGH] CVE-2014-1568: nss - Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, a...
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome
debian
CVE-2020-25648P3HIGHCVSS 7.5fixed in nss 2:3.58-1 (bookworm)2020
CVE-2020-25648 [HIGH] CVE-2020-25648: nss - A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1...
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Scope: local
bookworm: resolved (fixe
debian
CVE-2014-1569P3HIGHCVSS 7.5fixed in nss 2:3.17.2-1.1 (bookworm)2014
CVE-2014-1569 [HIGH] CVE-2014-1569: nss - The definite_length_decoder function in lib/util/quickder.c in Mozilla Network S...
The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeI
debian
CVE-2015-7181P3HIGHCVSS 7.5fixed in nss 2:3.20.1-1 (bookworm)2015
CVE-2015-7181 [HIGH] CVE-2015-7181: nss - The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) bef...
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary
debian
1 / 4Next →