4.3

CVE-2014-1491

Exploit
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version < 24.3
Mozilla ≫ Firefox Version < 27.0
Mozilla ≫ Network Security Services Version < 3.15.4
Mozilla ≫ Seamonkey Version < 2.24
Mozilla ≫ Thunderbird Version < 24.3.0
Oracle ≫ Vm Server Version 3.2 HwPlatform x86
Fedoraproject ≫ Fedora Version 19
Fedoraproject ≫ Fedora Version 20
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.3
Opensuse ≫ Opensuse Version 13.1
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.66% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23
Not Applicable
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
Third Party Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Not Applicable
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
Not Applicable
https://security.gentoo.org/glsa/201504-01
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
Third Party Advisory
http://www.debian.org/security/2014/dsa-2994
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/56858
Third Party Advisory
http://secunia.com/advisories/56888
Third Party Advisory
http://www.debian.org/security/2014/dsa-2858
Third Party Advisory
http://www.securitytracker.com/id/1029717
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1029720
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1029721
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2102-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2102-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-2119-1
Third Party Advisory
http://secunia.com/advisories/56922
Third Party Advisory
http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
Third Party Advisory
Vendor Advisory
http://hg.mozilla.org/projects/nss/rev/12c42006aed8
Patch
Vendor Advisory
http://www.securityfocus.com/bid/65332
Third Party Advisory
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=934545
Patch
Vendor Advisory
Exploit
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
Third Party Advisory
VDB Entry