4.3
CVE-2011-5094
- EPSS 4.56%
- Veröffentlicht 16.06.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Network Security Services Version3.2
Mozilla ≫ Network Security Services Version3.2.1
Mozilla ≫ Network Security Services Version3.3
Mozilla ≫ Network Security Services Version3.3.1
Mozilla ≫ Network Security Services Version3.3.2
Mozilla ≫ Network Security Services Version3.4
Mozilla ≫ Network Security Services Version3.4.1
Mozilla ≫ Network Security Services Version3.4.2
Mozilla ≫ Network Security Services Version3.5
Mozilla ≫ Network Security Services Version3.6
Mozilla ≫ Network Security Services Version3.6.1
Mozilla ≫ Network Security Services Version3.7
Mozilla ≫ Network Security Services Version3.7.1
Mozilla ≫ Network Security Services Version3.7.2
Mozilla ≫ Network Security Services Version3.7.3
Mozilla ≫ Network Security Services Version3.7.5
Mozilla ≫ Network Security Services Version3.7.7
Mozilla ≫ Network Security Services Version3.8
Mozilla ≫ Network Security Services Version3.9
Mozilla ≫ Network Security Services Version3.11.2
Mozilla ≫ Network Security Services Version3.11.3
Mozilla ≫ Network Security Services Version3.11.4
Mozilla ≫ Network Security Services Version3.11.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 4.56% | 0.888 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|