Vulnerabilities > Mozilla > Network Security Services > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-3479 Unspecified vulnerability in Mozilla Network Security Services 3.77
A vulnerability found in nss.
network
low complexity
mozilla
7.5
2020-10-22 CVE-2019-17007 Improper Certificate Validation vulnerability in multiple products
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
network
low complexity
mozilla siemens CWE-295
7.5
2020-10-20 CVE-2020-25648 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3.
network
low complexity
mozilla redhat fedoraproject oracle CWE-770
7.5
2017-12-27 CVE-2017-11698 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11697 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11696 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11695 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-05-30 CVE-2017-7502 Unspecified vulnerability in Mozilla Network Security Services
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
network
low complexity
mozilla
7.5
2016-06-13 CVE-2016-2834 Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
network
low complexity
canonical opensuse mozilla novell
8.8
2016-03-13 CVE-2016-1979 Unspecified vulnerability in Mozilla Firefox
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
network
low complexity
mozilla
8.8