Mozilla Network Security Services (NSS) 3.44.1

CPE Details

Mozilla Network Security Services (NSS) 3.44.1
3.44.1
2020-10-28
17h33 +00:00
2020-10-28
17h33 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mozilla:network_security_services:3.44.1:*:*:*:*:*:*:*

Informations

Vendor

mozilla

Product

network_security_services

Version

3.44.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-17006 2020-10-22 18h24 +00:00 In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
9.8
Critical
CVE-2020-25648 2020-10-19 22h00 +00:00 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
7.5
High