Mozilla Nss vulnerabilities
77 known vulnerabilities affecting mozilla/nss.
Total CVEs
77
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH25MEDIUM37LOW4
Vulnerabilities
Page 2 of 4
CVE-2015-7181P3HIGHCVSS 7.5≥ 0, < 2:3.20.1-12015-11-05
CVE-2015-7181 [HIGH] CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code
osv
CVE-2019-11745P3HIGHCVSS 8.8≥ 0, < 2:3.47.1-12020-01-08
CVE-2019-11745 [HIGH] CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox
osv
CVE-2024-6609P3HIGHCVSS 8.8≥ 0, < 2:3.61-1+deb11u4≥ 0, < 2:3.87.1-1+deb12u1+1 more2024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed again
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
osv
CVE-2009-2404P3CRITICALCVSS 9.3≥ 0, < 3.12.3-12009-08-03
CVE-2009-2404 [CRITICAL] CVE-2009-2404: Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in th
osv
CVE-2017-7502P3HIGHCVSS 7.5≥ 0, < 2:3.26.2-1.12017-05-30
CVE-2017-7502 [HIGH] CVE-2017-7502: Null pointer dereference vulnerability in NSS since 3
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
osv
CVE-2022-34480P3HIGHCVSS 8.8≥ 0, < 2:3.28.4-0ubuntu0.14.04.5+esm11≥ 0, < 2:3.28.4-0ubuntu0.16.04.14+esm3+3 more2022-07-05
CVE-2022-34480 [HIGH] CVE-2022-34480: Within the lg_init() function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being a
Within the lg_init() function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.
osv
CVE-2019-11719P3HIGHCVSS 7.5≥ 0, < 2:3.28.4-0ubuntu0.16.04.6≥ 0, < 2:3.35-2ubuntu2.32019-07-16
CVE-2019-11719 [HIGH] nss vulnerabilities
nss vulnerabilities
Henry Corrigan-Gibbs discovered that NSS incorrectly handled importing
certain curve25519 private keys. An attacker could use this issue to cause
NSS to crash, resulting in a denial of service, or possibly obtain
sensitive information. (CVE-2019-11719)
Hubert Kario discovered that NSS incorrectly handled PKCS#1 v1.5 signatures
when using TLSv1.3. An attacker could possibly use this issue to trick NSS
into using PKCS#1 v1.5 signature
osv
CVE-2024-0743P3HIGHCVSS 7.5≥ 0, < 2:3.61-1+deb11u4≥ 0, < 2:3.87.1-1+deb12u1+1 more2024-01-23
CVE-2024-0743 [HIGH] CVE-2024-0743: An unchecked return value in TLS handshake code could have caused a potentially exploitable crash
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
osv
CVE-2016-1979P3HIGHCVSS 8.8≥ 0, < 2:3.21-12016-03-13
CVE-2016-1979 [HIGH] CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
osv
CVE-2017-7805P3HIGHCVSS 7.5≥ 0, < 2:3.33-12018-06-11
CVE-2017-7805 [HIGH] CVE-2017-7805: During TLS 1
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploi
osv
CVE-2016-2834P3HIGHCVSS 8.8≥ 0, < 2:3.23-12016-06-13
CVE-2016-2834 [HIGH] CVE-2016-2834: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
osv
CVE-2013-5605P3HIGHCVSS 7.5≥ 0, < 2:3.15.3-12013-11-18
CVE-2013-5605 [HIGH] CVE-2013-5605: Mozilla Network Security Services (NSS) 3
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
osv
CVE-2013-1741P3HIGHCVSS 7.5≥ 0, < 2:3.15.3-12013-11-18
CVE-2013-1741 [HIGH] CVE-2013-1741: Integer overflow in Mozilla Network Security Services (NSS) 3
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
osv
CVE-2014-1490P3CRITICALCVSS 9.3≥ 0, < 2:3.15.4-12014-02-06
CVE-2014-1490 [CRITICAL] CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that
osv
CVE-2016-5285P3HIGHCVSS 7.5fixed in 3.262019-11-15
CVE-2016-5285 [HIGH] CWE-476 CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missin
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
nvdosv
CVE-2022-3479P3HIGHCVSS 7.5≥ 0, < 2:3.35-2ubuntu2.16≥ 0, < 2:3.49.1-1ubuntu1.9+1 more2023-02-27
CVE-2022-3479 [HIGH] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled client authentication
without a user certificate in the database. A remote attacker could
possibly use this issue to cause a NSS client to crash, resulting in a
denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-3479)
Christian Holler discovered that NSS incorrectly handled certain PKCS 12
certificated bundles. A remote attacker could use this issue to cause NSS
to crash
osv
CVE-2010-3173P3HIGHCVSS 7.5≥ 0, < 3.12.8-12010-10-21
CVE-2010-3173 [HIGH] CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
osv
CVE-2016-1978P3HIGHCVSS 7.3≥ 0, < 2:3.21-12016-03-13
CVE-2016-1978 [HIGH] CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high
osv
CVE-2019-17007P3HIGHCVSS 7.5≥ unspecified, < 3.442020-10-22
CVE-2019-17007 [HIGH] CWE-295 CVE-2019-17007: In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
nvdosv
CVE-2023-4421P3MEDIUMCVSS 6.5fixed in 3.6.1≥ unspecified, < 3.612023-12-12
CVE-2023-4421 [MEDIUM] CWE-203 CVE-2023-4421: The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previous
nvdosv