Mozilla / Network Security Services
50 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-3479 | nss: nss client auth crash without a user certificate in the database | HIGH | 7.5 | Oct 14, 2022 |
| CVE-2019-17007 | nss: Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may crash with a NULL deref leading to DoS | HIGH | 7.5 | Oct 22, 2020 |
| CVE-2019-17006 | nss: Check length of inputs for cryptographic primitives | CRITICAL | 9.8 | Oct 22, 2020 |
| CVE-2018-18508 | nss: NULL pointer dereference in several CMS functions resulting in a denial of service | MEDIUM | 6.5 | Oct 22, 2020 |
| CVE-2020-25648 | nss: TLS 1.3 CCS flood remote DoS Attack | HIGH | 7.5 | Oct 20, 2020 |
| CVE-2016-5285 | nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash | HIGH | 7.5 | Nov 15, 2019 |
| CVE-2018-12404 | nss: Cache side-channel variant of the Bleichenbacher attack | MEDIUM | 5.9 | May 2, 2019 |
| CVE-2018-12384 | nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello | MEDIUM | 5.9 | Apr 29, 2019 |
| CVE-2016-8635 | nss: small-subgroups attack flaw | MEDIUM | 5.9 | Aug 1, 2018 |
| CVE-2016-9574 | nss: Remote DoS during session handshake when using SessionTicket extention and ECDHE-ECDSA | MEDIUM | 5.9 | Jul 19, 2018 |
| CVE-2017-5462 | nss: DRBG flaw in NSS | MEDIUM | 5.3 | Jun 11, 2018 |
| CVE-2017-11698 | nss: Heap-buffer-overflow in __get_page | HIGH | 7.8 | Dec 27, 2017 |
| CVE-2017-11697 | nss: Floating Point Exception in __hash_open | HIGH | 7.8 | Dec 27, 2017 |
| CVE-2017-11696 | nss: Heap-buffer-overflow in __hash_open | HIGH | 7.8 | Dec 27, 2017 |
| CVE-2017-11695 | nss: Heap-buffer-overflow in alloc_segs | HIGH | 7.8 | Dec 27, 2017 |
| CVE-2017-7502 | nss: Null pointer dereference when handling empty SSLv2 messages | HIGH | 7.5 | May 30, 2017 |
| CVE-2017-5461 | nss: Write beyond bounds caused by bugs in Base64 de/encoding in nssb64d.c and nssb64e.c (MFSA 2017-10) | CRITICAL | 9.8 | May 11, 2017 |
| CVE-2016-2834 | nss: Multiple security flaws (MFSA 2016-61) | HIGH | 8.8 | Jun 13, 2016 |
| CVE-2016-1979 | nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36) | HIGH | 8.8 | Mar 13, 2016 |
| CVE-2016-1978 | nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15) | HIGH | 7.3 | Mar 13, 2016 |
| CVE-2016-1950 | nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35) | HIGH | 8.8 | Mar 13, 2016 |
| CVE-2015-7575 | TLS 1.2 Transcipt Collision attacks against MD5 in key exchange protocol (SLOTH) | MEDIUM | 5.9 | Jan 9, 2016 |
| CVE-2015-7183 | nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133) | HIGH | 7.5 | Nov 5, 2015 |
| CVE-2015-7182 | nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133) | CRITICAL | 9.8 | Nov 5, 2015 |
| CVE-2015-7181 | nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133) | HIGH | 7.5 | Nov 5, 2015 |
Showing 1 to 25 of 50 CVEs