7.5
CVE-2014-1568
- EPSS 35.36%
- Veröffentlicht 25.09.2014 17:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle security@mozilla.org
- Teams Watchlist Login
- Unerledigt Login
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox ESR Version24.8.0
Mozilla ≫ Network Security Services Version <= 3.16.2.0
Mozilla ≫ Network Security Services Version3.2
Mozilla ≫ Network Security Services Version3.2.1
Mozilla ≫ Network Security Services Version3.3
Mozilla ≫ Network Security Services Version3.3.1
Mozilla ≫ Network Security Services Version3.3.2
Mozilla ≫ Network Security Services Version3.4
Mozilla ≫ Network Security Services Version3.4.1
Mozilla ≫ Network Security Services Version3.4.2
Mozilla ≫ Network Security Services Version3.5
Mozilla ≫ Network Security Services Version3.6
Mozilla ≫ Network Security Services Version3.6.1
Mozilla ≫ Network Security Services Version3.7
Mozilla ≫ Network Security Services Version3.7.1
Mozilla ≫ Network Security Services Version3.7.2
Mozilla ≫ Network Security Services Version3.7.3
Mozilla ≫ Network Security Services Version3.7.5
Mozilla ≫ Network Security Services Version3.7.7
Mozilla ≫ Network Security Services Version3.8
Mozilla ≫ Network Security Services Version3.9
Mozilla ≫ Network Security Services Version3.11.2
Mozilla ≫ Network Security Services Version3.11.3
Mozilla ≫ Network Security Services Version3.11.4
Mozilla ≫ Network Security Services Version3.11.5
Mozilla ≫ Network Security Services Version3.12
Mozilla ≫ Network Security Services Version3.12.1
Mozilla ≫ Network Security Services Version3.12.2
Mozilla ≫ Network Security Services Version3.12.3
Mozilla ≫ Network Security Services Version3.12.3.1
Mozilla ≫ Network Security Services Version3.12.3.2
Mozilla ≫ Network Security Services Version3.12.4
Mozilla ≫ Network Security Services Version3.12.5
Mozilla ≫ Network Security Services Version3.12.6
Mozilla ≫ Network Security Services Version3.12.7
Mozilla ≫ Network Security Services Version3.12.8
Mozilla ≫ Network Security Services Version3.12.9
Mozilla ≫ Network Security Services Version3.12.10
Mozilla ≫ Network Security Services Version3.12.11
Mozilla ≫ Network Security Services Version3.14
Mozilla ≫ Network Security Services Version3.14.1
Mozilla ≫ Network Security Services Version3.14.2
Mozilla ≫ Network Security Services Version3.14.3
Mozilla ≫ Network Security Services Version3.14.4
Mozilla ≫ Network Security Services Version3.14.5
Mozilla ≫ Network Security Services Version3.15
Mozilla ≫ Network Security Services Version3.15.1
Mozilla ≫ Network Security Services Version3.15.2
Mozilla ≫ Network Security Services Version3.15.3
Mozilla ≫ Network Security Services Version3.15.3.1
Mozilla ≫ Network Security Services Version3.15.4
Mozilla ≫ Network Security Services Version3.15.5
Mozilla ≫ Network Security Services Version3.16
Mozilla ≫ Network Security Services Version3.16.1
Mozilla ≫ Network Security Services Version3.16.3
Mozilla ≫ Network Security Services Version3.16.4
Mozilla ≫ Thunderbird Version <= 24.8.0
Mozilla ≫ Thunderbird Version31.0
Mozilla ≫ Thunderbird Version31.1.0
Mozilla ≫ Thunderbird Version31.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 35.36% | 0.969 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|