4.3
CVE-2011-5094
- EPSS 3.44%
- Veröffentlicht 16.06.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Network Security Services Version3.2
Mozilla ≫ Network Security Services Version3.2.1
Mozilla ≫ Network Security Services Version3.3
Mozilla ≫ Network Security Services Version3.3.1
Mozilla ≫ Network Security Services Version3.3.2
Mozilla ≫ Network Security Services Version3.4
Mozilla ≫ Network Security Services Version3.4.1
Mozilla ≫ Network Security Services Version3.4.2
Mozilla ≫ Network Security Services Version3.5
Mozilla ≫ Network Security Services Version3.6
Mozilla ≫ Network Security Services Version3.6.1
Mozilla ≫ Network Security Services Version3.7
Mozilla ≫ Network Security Services Version3.7.1
Mozilla ≫ Network Security Services Version3.7.2
Mozilla ≫ Network Security Services Version3.7.3
Mozilla ≫ Network Security Services Version3.7.5
Mozilla ≫ Network Security Services Version3.7.7
Mozilla ≫ Network Security Services Version3.8
Mozilla ≫ Network Security Services Version3.9
Mozilla ≫ Network Security Services Version3.11.2
Mozilla ≫ Network Security Services Version3.11.3
Mozilla ≫ Network Security Services Version3.11.4
Mozilla ≫ Network Security Services Version3.11.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.44% | 0.87 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|