cbcvebase.

Mozilla Network Security Services vulnerabilities

47 known vulnerabilities affecting mozilla/network_security_services.

Total CVEs
47
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM24LOW1

Vulnerabilities

Page 2 of 3
CVE-2014-1490P3CRITICALCVSS 9.3fixed in 3.15.42014-02-06
CVE-2014-1490 [CRITICAL] CWE-362 CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozill Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involv
nvd
CVE-2016-5285P3HIGHCVSS 7.5v3.242019-11-15
CVE-2016-5285 [HIGH] CWE-476 CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missin A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2022-3479P3HIGHCVSS 7.5≥ 3.77, < 3.872022-10-14
CVE-2022-3479 [HIGH] CVE-2022-3479: A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user c A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
nvd
CVE-2007-0008P3MEDIUMCVSS 6.8v3.11.2v3.11.3+1 more2007-02-26
CVE-2007-0008 [MEDIUM] CWE-189 CVE-2007-0008: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message
nvd
CVE-2016-1978P3HIGHCVSS 7.3≤ 3.20.12016-03-13
CVE-2016-1978 [HIGH] CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Sec Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
nvd
CVE-2019-17007P3HIGHCVSS 7.5fixed in 3.442020-10-22
CVE-2019-17007 [HIGH] CWE-295 CVE-2019-17007: In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
nvd
CVE-2013-5606P4MEDIUMCVSS 5.8v3.15v3.15.1+1 more2013-11-18
CVE-2013-5606 [MEDIUM] CWE-264 CVE-2013-5606: The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3. The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
nvd
CVE-2009-2408P4MEDIUMCVSS 5.9fixed in 3.12.32009-07-30
CVE-2009-2408 [MEDIUM] CWE-295 CVE-2009-2408: Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificat
nvd
CVE-2015-7575P4MEDIUMCVSS 5.9≤ 3.20.12016-01-09
CVE-2015-7575 [MEDIUM] CWE-19 CVE-2015-7575: Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
nvd
CVE-2016-8635P4MEDIUMCVSS 5.9≥ 3.21, ≤ 3.21.42018-08-01
CVE-2016-8635 [MEDIUM] CWE-358 CVE-2016-8635: It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
nvd
CVE-2018-12384P4MEDIUMCVSS 5.9fixed in 3.392019-04-29
CVE-2018-12384 [MEDIUM] CWE-335 CVE-2018-12384: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
nvd
CVE-2013-1740P4MEDIUMCVSS 5.8≤ 3.15.3v3.2+45 more2014-01-18
CVE-2013-1740 [MEDIUM] CWE-310 CVE-2013-1740: The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) b The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
nvd
CVE-2018-18508P4MEDIUMCVSS 6.5fixed in 3.36.7≥ 3.41, < 3.41.12020-10-22
CVE-2018-18508 [MEDIUM] CWE-476 CVE-2018-18508: In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
nvd
CVE-2009-2409P4MEDIUMCVSS 5.1fixed in 3.12.32009-07-30
CVE-2009-2409 [MEDIUM] CWE-295 CVE-2009-2409: The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 a The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scop
nvd
CVE-2017-5462P4MEDIUMCVSS 5.3fixed in 3.28.42018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2006-5462P4MEDIUMCVSS 6.4v3.11.32006-11-08
CVE-2006-5462 [MEDIUM] CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5. Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier i
nvd
CVE-2013-0791P4MEDIUMCVSS 5.0fixed in 3.152013-04-03
CVE-2013-0791 [MEDIUM] CWE-119 CVE-2013-0791: The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla F The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption)
nvd
CVE-2013-1739P4MEDIUMCVSS 5.0≤ 3.15.1v3.12+18 more2013-10-22
CVE-2013-1739 [MEDIUM] CVE-2013-1739: Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initi Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3fixed in 3.15.42014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2016-9574P4MEDIUMCVSS 5.9fixed in 3.302018-07-19
CVE-2016-9574 [MEDIUM] CWE-325 CVE-2016-9574: nss before version 3.30 is vulnerable to a remote denial of service during the session handshake whe nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
nvd
Mozilla Network Security Services vulnerabilities | cvebase