Vulnerabilities > MOD NSS Project

DATE CVE VULNERABILITY TITLE RISK
2018-02-15 CVE-2011-4973 Improper Authentication vulnerability in MOD NSS Project MOD NSS 1.0.8
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.
network
low complexity
mod-nss-project CWE-287
critical
9.8
2017-08-09 CVE-2015-3277 Information Exposure vulnerability in MOD NSS Project MOD NSS
The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of multi-keyword cipherstring.
network
low complexity
mod-nss-project CWE-200
7.5
2017-08-07 CVE-2015-5244 Permissions, Privileges, and Access Controls vulnerability in MOD NSS Project MOD NSS
The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.
network
low complexity
mod-nss-project CWE-264
critical
9.8