cbcvebase.

Mozilla Network Security Services vulnerabilities

47 known vulnerabilities affecting mozilla/network_security_services.

Total CVEs
47
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM24LOW1

Vulnerabilities

Page 1 of 3
CVE-2015-4000P3LOWCVSS 3.7PoCv3.192015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2007-0009P3MEDIUMCVSS 6.8fixed in 3.11.52007-02-26
CVE-2007-0009 [MEDIUM] CWE-119 CVE-2007-0009: Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3 Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Mas
nvd
CVE-2018-12404P3MEDIUMCVSS 5.9fixed in 3.41vAll versions prior to NSS 3.412019-05-02
CVE-2018-12404 [MEDIUM] CVE-2018-12404: A cached side channel attack during handshakes using RSA encryption could allow for the decryption o A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
nvd
CVE-2019-17006P3CRITICALCVSS 9.8fixed in 3.462020-10-22
CVE-2019-17006 [CRITICAL] CWE-20 CVE-2019-17006: In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
nvd
CVE-2015-7182P3CRITICALCVSS 9.8≤ 3.19.2.0v3.20.02015-11-05
CVE-2015-7182 [CRITICAL] CWE-119 CVE-2015-7182: Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3. Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING d
nvd
CVE-2017-5461P3CRITICALCVSS 9.8fixed in 3.21.4fixed in 3.28.4+2 more2017-05-11
CVE-2017-5461 [CRITICAL] CWE-787 CVE-2017-5461: Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x b Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
nvd
CVE-2016-1950P3HIGHCVSS 8.8v3.19.2v3.20+2 more2016-03-13
CVE-2016-1950 [HIGH] CWE-119 CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
nvd
CVE-2014-1544P3CRITICALCVSS 10.0v3.2v3.2.1+49 more2014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Networ Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a
nvd
CVE-2004-0826P3HIGHCVSS 7.5v3.2v3.2.1+17 more2004-12-31
CVE-2004-0826 [HIGH] CVE-2004-0826: Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attacke Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
nvd
CVE-2014-1568P3HIGHCVSS 7.5≤ 3.16.2.0v3.2+53 more2014-09-25
CVE-2014-1568 [HIGH] CWE-310 CVE-2014-1568: Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.1 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X
nvd
CVE-2020-25648P3HIGHCVSS 7.5fixed in 3.582020-10-20
CVE-2020-25648 [HIGH] CWE-770 CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
nvd
CVE-2014-1569P3HIGHCVSS 7.5≤ 3.16.2.3v3.16.2.0+5 more2014-12-15
CVE-2014-1569 [HIGH] CVE-2014-1569: The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NS The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_Quic
nvd
CVE-2015-7181P3HIGHCVSS 7.5≤ 3.19.2.0v3.20.02015-11-05
CVE-2015-7181 [HIGH] CWE-119 CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.2 The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly
nvd
CVE-2015-7183P3HIGHCVSS 7.5≤ 3.19.2.0v3.20.02015-11-05
CVE-2015-7183 [HIGH] CWE-119 CVE-2015-7183: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozi Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup
nvd
CVE-2009-2404P3CRITICALCVSS 9.3v3.12.32009-08-03
CVE-2009-2404 [CRITICAL] CWE-119 CVE-2009-2404: Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the
nvd
CVE-2017-7502P3HIGHCVSS 7.5v3.24.0v3.25.0+16 more2017-05-30
CVE-2017-7502 [HIGH] CWE-476 CVE-2017-7502: Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
nvd
CVE-2016-1979P3HIGHCVSS 8.8≤ 3.212016-03-13
CVE-2016-1979 [HIGH] CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Net Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
nvd
CVE-2016-2834P3HIGHCVSS 8.8≤ 3.222016-06-13
CVE-2016-2834 [HIGH] CVE-2016-2834: Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-5605P3HIGHCVSS 7.5v3.14v3.14.1+6 more2013-11-18
CVE-2013-5605 [HIGH] CWE-20 CVE-2013-5605: Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote atta Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
nvd
CVE-2013-1741P3HIGHCVSS 7.5v3.15v3.15.1+1 more2013-11-18
CVE-2013-1741 [HIGH] CWE-189 CVE-2013-1741: Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attacke Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
nvd
Mozilla Network Security Services vulnerabilities | cvebase