Mozilla Network Security Services 3.39

CPE Details

Mozilla Network Security Services 3.39
3.39
2019-05-01
14h47 +00:00
2019-05-01
14h47 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:mozilla:network_security_services:3.39:*:*:*:*:*:*:*

Informations

Vendor

mozilla

Product

network_security_services

Version

3.39

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-17007 2020-10-22 18h28 +00:00 In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
7.5
Haute
CVE-2019-17006 2020-10-22 18h24 +00:00 In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
9.8
Critique
CVE-2020-25648 2020-10-19 22h00 +00:00 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
7.5
Haute
CVE-2018-12404 2019-05-02 14h40 +00:00 A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
5.9
Moyen