Mozilla / NSS
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-4421 | nss: new tlsfuzzer code can still detect timing issues in RSA operations | MEDIUM | 6.5 | Dec 12, 2023 |
| CVE-2021-43527 | nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) | CRITICAL | 9.8 | Dec 8, 2021 |
| CVE-2020-12403 | nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read | CRITICAL | 9.1 | May 27, 2021 |
| CVE-2019-17007 | nss: Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may crash with a NULL deref leading to DoS | HIGH | 7.5 | Oct 22, 2020 |
| CVE-2019-17006 | nss: Check length of inputs for cryptographic primitives | CRITICAL | 9.8 | Oct 22, 2020 |
| CVE-2018-18508 | nss: NULL pointer dereference in several CMS functions resulting in a denial of service | MEDIUM | 6.5 | Oct 22, 2020 |
| CVE-2016-5285 | nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash | HIGH | 7.5 | Nov 15, 2019 |
| CVE-2016-8635 | nss: small-subgroups attack flaw | MEDIUM | 5.9 | Aug 1, 2018 |
| CVE-2016-1938 | NSS: Errors in mp_div and mp_exptmod cryptographic functions | MEDIUM | 6.5 | Jan 31, 2016 |
| CVE-2009-3555 | TLS: MITM attacks via session renegotiation | CRITICAL | 9.8 | Nov 9, 2009 |
Showing 1 to 7 of 7 CVEs