cbcvebase.

Debian Nss vulnerabilities

74 known vulnerabilities affecting debian/nss.

Total CVEs
74
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH20MEDIUM33LOW12

Vulnerabilities

Page 2 of 4
CVE-2019-11745P3HIGHCVSS 8.8fixed in nss 2:3.47.1-1 (bookworm)2019
CVE-2019-11745 [HIGH] CVE-2019-11745: nss - When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made wit... When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local bookworm: resolved (fixed in 2:3.47.1-1)
debian
CVE-2024-6609P3HIGHCVSS 8.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6609 [HIGH] CVE-2024-6609: firefox - When almost out-of-memory an elliptic curve key which was never allocated could ... When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2009-2404P3LOWCVSS 9.3fixed in nss 3.12.3-1 (bookworm)2009
CVE-2009-2404 [CRITICAL] CVE-2009-2404: nss - Heap-based buffer overflow in a regular-expression parser in Mozilla Network Sec... Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common N
debian
CVE-2017-7502P3HIGHCVSS 7.5fixed in nss 2:3.26.2-1.1 (bookworm)2017
CVE-2017-7502 [HIGH] CVE-2017-7502: nss - Null pointer dereference vulnerability in NSS since 3.24.0 was found when server... Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker. Scope: local bookworm: resolved (fixed in 2:3.26.2-1.1) bullseye: resolved (fixed in 2:3.26.2-1.1) forky: resolved (fixed in 2:3.26.2-1.1) sid: resolved (fixed in 2:3.26.2-1.1) trixie: resolved (fixed in 2:3.26
debian
CVE-2019-11719P3LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11719 [HIGH] CVE-2019-11719: firefox - When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes,... When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2024-0743P3HIGHCVSS 7.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0743 [HIGH] CVE-2024-0743: firefox - An unchecked return value in TLS handshake code could have caused a potentially ... An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2016-1979P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1979 [HIGH] CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun... Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2017-7805P3HIGHCVSS 7.5fixed in firefox 56.0-1 (sid)2017
CVE-2017-7805 [HIGH] CVE-2017-7805: firefox - During TLS 1.2 exchanges, handshake hashes are generated which point to a messag... During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handsha
debian
CVE-2016-2834P3HIGHCVSS 8.8fixed in firefox 47.0-1 (sid)2016
CVE-2016-2834 [HIGH] CVE-2016-2834: firefox - Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox ... Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. Scope: local sid: resolved (fixed in 47.0-1)
debian
CVE-2013-5605P3HIGHCVSS 7.5fixed in nss 2:3.15.3-1 (bookworm)2013
CVE-2013-5605 [HIGH] CVE-2013-5605: nss - Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.... Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets. Scope: local bookworm: resolved (fixed in 2:3.15.3-1) bullseye: resolved (fixed in 2:3.15.3-1) forky: resolved (fixed in 2:3.15.3-1) sid: resolved (fixed in 2:3.15.3-
debian
CVE-2013-1741P3HIGHCVSS 7.5fixed in nss 2:3.15.3-1 (bookworm)2013
CVE-2013-1741 [HIGH] CVE-2013-1741: nss - Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 a... Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value. Scope: local bookworm: resolved (fixed in 2:3.15.3-1) bullseye: resolved (fixed in 2:3.15.3-1) forky: resolved (fixed in 2:3.15.3-1) sid: resolved (fixed in 2:3.15.3-1) trixie:
debian
CVE-2014-1490P3CRITICALCVSS 9.3fixed in nss 2:3.15.4-1 (bookworm)2014
CVE-2014-1490 [CRITICAL] CVE-2014-1490: nss - Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.... Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption ha
debian
CVE-2016-5285P3HIGHCVSS 7.5fixed in nss 2:3.25-1 (bookworm)2016
CVE-2016-5285 [HIGH] CVE-2016-5285: nss - A Null pointer dereference vulnerability exists in Mozilla Network Security Serv... A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. Scope: local bookworm: resolved (fixed in 2:3.25-1) bullseye: resolved (fixed in 2:3.25-1) forky: resolved (fixed in 2:3.25-1) sid: re
debian
CVE-2022-3479P3HIGHCVSS 7.5fixed in nss 2:3.87-1 (bookworm)2022
CVE-2022-3479 [HIGH] CVE-2022-3479: nss - A vulnerability found in nss. By this security vulnerability, nss client auth cr... A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash. Scope: local bookworm: resolved (fixed in 2:3.87-1) bullseye: resolved forky: resolved (fixed in 2:3.87-1) sid: resolved (fixed in 2:3.87-1) trixie: resolved (fixed in 2:3.87-1)
debian
CVE-2010-3173P3HIGHCVSS 7.5fixed in nss 3.12.8-1 (bookworm)2010
CVE-2010-3173 [HIGH] CVE-2010-3173: nss - The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11,... The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. Scope: local boo
debian
CVE-2016-1978P3HIGHCVSS 7.3fixed in nss 2:3.21-1 (bookworm)2016
CVE-2016-1978 [HIGH] CVE-2016-1978: nss - Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in... Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. Scope: local bookwo
debian
CVE-2019-17007P3HIGHCVSS 7.5fixed in nss 2:3.45-1 (bookworm)2019
CVE-2019-17007 [HIGH] CVE-2019-17007: nss - In Network Security Services before 3.44, a malformed Netscape Certificate Seque... In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. Scope: local bookworm: resolved (fixed in 2:3.45-1) bullseye: resolved (fixed in 2:3.45-1) forky: resolved (fixed in 2:3.45-1) sid: resolved (fixed in 2:3.45-1) trixie: resolved (fixed in 2:3.45-1)
debian
CVE-2023-4421P3MEDIUMCVSS 6.5fixed in nss 2:3.61-1 (bookworm)2023
CVE-2023-4421 [MEDIUM] CVE-2023-4421: nss - The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mou... The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS
debian
CVE-2019-11729P4LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11729 [HIGH] CVE-2019-11729: firefox - Empty or malformed p256-ECDH public keys may trigger a segmentation fault due va... Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2016-1938P4MEDIUMCVSS 6.5fixed in nss 2:3.21-1 (bookworm)2016
CVE-2016-1938 [MEDIUM] CVE-2016-1938: nss - The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Servic... The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function. Scope: local bookworm: resolved (fixed in 2:
debian