cbcvebase.

Mozilla Nss vulnerabilities

77 known vulnerabilities affecting mozilla/nss.

Total CVEs
77
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH25MEDIUM37LOW4

Vulnerabilities

Page 1 of 4
CVE-2009-3555P1CRITICALCVSS 9.8ExploitedPoC≤ 3.12.42009-11-09
CVE-2009-3555 [CRITICAL] CWE-295 CVE-2009-3555: The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Infor The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properl
nvdosv
CVE-2016-2183P2HIGHCVSS 7.5PoC≥ 0, < 2:3.28.4-0ubuntu0.14.04.1≥ 0, < 2:3.28.4-0ubuntu0.16.04.12017-04-27
CVE-2016-2183 [HIGH] nss vulnerabilities nss vulnerabilities Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES ciphers were vulnerable to birthday attacks. A remote attacker could possibly use this flaw to obtain clear text data from long encrypted sessions. This update causes NSS to limit use of the same symmetric key. (CVE-2016-2183) It was discovered that NSS incorrectly handled Base64 decoding. A remote attacker could use this flaw to cause NSS to crash, resulting
osv
CVE-2016-0800P2MEDIUMCVSS 5.9PoC≥ 0, < 3.132016-03-01
CVE-2016-0800 [MEDIUM] CVE-2016-0800: The SSLv2 protocol, as used in OpenSSL before 1 The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
osv
CVE-2015-4000P3LOWCVSS 3.7PoC≥ 0, < 2:3.19.1-12015-05-21
CVE-2015-4000 [LOW] CVE-2015-4000: The TLS protocol 1 The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
osv
CVE-2014-3566P3LOWCVSS 3.4PoC≥ 0, < 2:3.17.1-12014-10-15
CVE-2014-3566 [LOW] CVE-2014-3566: The SSL protocol 3 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
osv
CVE-2011-3389P3MEDIUMCVSS 4.3PoC≥ 0, < 3.13.1.with.ckbi.1.88-12011-09-06
CVE-2011-3389 [MEDIUM] CVE-2011-3389: The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and o The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via
osv
CVE-2021-43527P2CRITICALCVSS 9.8fixed in 3.732021-12-08
CVE-2021-43527 [CRITICAL] CWE-787 CVE-2021-43527: NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overfl NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.50
nvdosv
CVE-2018-12404P3MEDIUMCVSS 5.9≥ 0, < 2:3.41-12019-05-02
CVE-2018-12404 [MEDIUM] CVE-2018-12404: A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
osv
CVE-2019-17006P3CRITICALCVSS 9.8≥ unspecified, < 3.462020-10-22
CVE-2019-17006 [CRITICAL] CWE-20 CVE-2019-17006: In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
nvdosv
CVE-2015-7182P3CRITICALCVSS 9.8≥ 0, < 2:3.20.1-12015-11-05
CVE-2015-7182 [CRITICAL] CVE-2015-7182: Heap-based buffer overflow in the ASN Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
osv
CVE-2017-5461P3CRITICALCVSS 9.8≥ 0, < 2:3.26.2-1.12017-05-11
CVE-2017-5461 [CRITICAL] CVE-2017-5461: Mozilla Network Security Services (NSS) before 3 Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
osv
CVE-2016-1950P3HIGHCVSS 8.8≥ 0, < 2:3.23-12016-03-13
CVE-2016-1950 [HIGH] CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3 Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
osv
CVE-2014-1544P3CRITICALCVSS 10.0≥ 0, < 2:3.16.3-12014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3 Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
osv
CVE-2020-12403P3CRITICALCVSS 9.1fixed in 3.55vnss 3.552021-05-27
CVE-2020-12403 [CRITICAL] CWE-125 CVE-2020-12403: A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When u A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to
nvdosv
CVE-2026-2781P3CRITICALCVSS 9.8≥ 0, < 2:3.61-1+deb11u5≥ 0, < 2:3.87.1-1+deb12u2+2 more2026-02-24
CVE-2026-2781 [CRITICAL] CVE-2026-2781: Integer overflow in the Libraries component in NSS Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
osv
CVE-2024-6602P3CRITICALCVSS 9.8≥ 0, < 2:3.61-1+deb11u4≥ 0, < 2:3.87.1-1+deb12u1+1 more2024-07-09
CVE-2024-6602 [CRITICAL] CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
osv
CVE-2023-0767P3HIGHCVSS 8.8≥ 0, < 2:3.61-1+deb11u3≥ 0, < 2:3.87.1-12023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mis An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
osv
CVE-2014-1568P3HIGHCVSS 7.5≥ 0, < 2:3.17.1-12014-09-25
CVE-2014-1568 [HIGH] CVE-2014-1568: Mozilla Network Security Services (NSS) before 3 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not proper
osv
CVE-2020-25648P3HIGHCVSS 7.5≥ 0, < 2:3.58-12020-10-20
CVE-2020-25648 [HIGH] CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
osv
CVE-2014-1569P3HIGHCVSS 7.5≥ 0, < 2:3.17.2-1.12014-12-15
CVE-2014-1569 [HIGH] CVE-2014-1569: The definite_length_decoder function in lib/util/quickder The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling
osv
Mozilla Nss vulnerabilities | cvebase