Debian Nss vulnerabilities
78 known vulnerabilities affecting debian/nss.
Total CVEs
78
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH20MEDIUM33LOW16
Vulnerabilities
Page 2 of 4
CVE-2019-17006CRITICALCVSS 9.8fixed in nss 2:3.47-1 (bookworm)2019
CVE-2019-17006 [CRITICAL] CVE-2019-17006: nss - In Network Security Services (NSS) before 3.46, several cryptographic primitives...
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2:3.47-1)
bullseye: resolved (fixed in 2:3.47-1)
forky: resolved (fix
debian
CVE-2019-11745HIGHCVSS 8.8fixed in nss 2:3.47.1-1 (bookworm)2019
CVE-2019-11745 [HIGH] CVE-2019-11745: nss - When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made wit...
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
bookworm: resolved (fixed in 2:3.47.1-1)
debian
CVE-2019-17007HIGHCVSS 7.5fixed in nss 2:3.45-1 (bookworm)2019
CVE-2019-17007 [HIGH] CVE-2019-17007: nss - In Network Security Services before 3.44, a malformed Netscape Certificate Seque...
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 2:3.45-1)
bullseye: resolved (fixed in 2:3.45-1)
forky: resolved (fixed in 2:3.45-1)
sid: resolved (fixed in 2:3.45-1)
trixie: resolved (fixed in 2:3.45-1)
debian
CVE-2019-17023MEDIUMCVSS 6.5fixed in firefox 72.0-1 (sid)2019
CVE-2019-17023 [MEDIUM] CVE-2019-17023: firefox - After a HelloRetryRequest has been sent, the client may negotiate a lower protoc...
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
Scope: local
sid: resolved (fixed in 72.0-1)
debian
CVE-2019-11729LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11729 [HIGH] CVE-2019-11729: firefox - Empty or malformed p256-ECDH public keys may trigger a segmentation fault due va...
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2019-11727LOWCVSS 5.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-11727 [MEDIUM] CVE-2019-11727: firefox - A vulnerability exists where it possible to force Network Security Services (NSS...
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.
Scope: local
sid: resolved (fixed in 68.0
debian
CVE-2019-11719LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11719 [HIGH] CVE-2019-11719: firefox - When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes,...
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2018-12404MEDIUMCVSS 5.9fixed in nss 2:3.41-1 (bookworm)2018
CVE-2018-12404 [MEDIUM] CVE-2018-12404: nss - A cached side channel attack during handshakes using RSA encryption could allow ...
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
Scope: local
bookworm: resolved (fixed in 2:3.41-1)
bullseye: resolved (fixed in 2:3.41-1)
forky: resolved (fixed
debian
CVE-2018-18508MEDIUMCVSS 6.5fixed in nss 2:3.42.1-1 (bookworm)2018
CVE-2018-18508 [MEDIUM] CVE-2018-18508: nss - In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed ...
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
Scope: local
bookworm: resolved (fixed in 2:3.42.1-1)
bullseye: resolved (fixed in 2:3.42.1-1)
forky: resolved (fixed in 2:3.42.1-1)
sid: resolved (fixed in 2:3.42.1-1)
trixie: resolved (fixed in 2:3.4
debian
CVE-2018-12384LOWCVSS 5.9fixed in nss 2:3.39-1 (bookworm)2018
CVE-2018-12384 [MEDIUM] CVE-2018-12384: nss - When handling a SSLv2-compatible ClientHello request, the server doesn't generat...
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Scope: local
bookworm: resolved (fixed in 2:3.39-1)
bullseye: resolved (fixed in 2:3.39
debian
CVE-2017-5461CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5461 [CRITICAL] CVE-2017-5461: firefox - Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x bef...
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-7805HIGHCVSS 7.5fixed in firefox 56.0-1 (sid)2017
CVE-2017-7805 [HIGH] CVE-2017-7805: firefox - During TLS 1.2 exchanges, handshake hashes are generated which point to a messag...
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handsha
debian
CVE-2017-7502HIGHCVSS 7.5fixed in nss 2:3.26.2-1.1 (bookworm)2017
CVE-2017-7502 [HIGH] CVE-2017-7502: nss - Null pointer dereference vulnerability in NSS since 3.24.0 was found when server...
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Scope: local
bookworm: resolved (fixed in 2:3.26.2-1.1)
bullseye: resolved (fixed in 2:3.26.2-1.1)
forky: resolved (fixed in 2:3.26.2-1.1)
sid: resolved (fixed in 2:3.26.2-1.1)
trixie: resolved (fixed in 2:3.26
debian
CVE-2017-5462MEDIUMCVSS 5.3fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5462 [MEDIUM] CVE-2017-5462: firefox - A flaw in DRBG number generation within the Network Security Services (NSS) libr...
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1
debian
CVE-2017-11696LOWCVSS 7.82017
CVE-2017-11696 [HIGH] CVE-2017-11696: nss - Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in ...
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2017-11695LOWCVSS 7.82017
CVE-2017-11695 [HIGH] CVE-2017-11695: nss - Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in M...
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2017-11697LOWCVSS 7.82017
CVE-2017-11697 [HIGH] CVE-2017-11697: nss - The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS...
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2017-11698LOWCVSS 7.82017
CVE-2017-11698 [HIGH] CVE-2017-11698: nss - Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in...
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2016-1950HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-1979HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1979 [HIGH] CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun...
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Scope: local
sid: resolved (fixed in 45.0-1)
debian