4.3
CVE-2015-2721
- EPSS 0.61%
- Published 06.07.2015 02:00:49
- Last modified 12.04.2025 10:46:40
- Source security@mozilla.org
- Teams watchlist Login
- Open Login
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
Data is provided by the National Vulnerability Database (NVD)
Novell ≫ Suse Linux Enterprise Software Development Kit Version12.0
Canonical ≫ Ubuntu Linux Version12.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version14.10
Canonical ≫ Ubuntu Linux Version15.04
Debian ≫ Debian Linux Version7.0
Debian ≫ Debian Linux Version8.0
Novell ≫ Suse Linux Enterprise Desktop Version12.0
Novell ≫ Suse Linux Enterprise Server Version11 Updatesp4
Novell ≫ Suse Linux Enterprise Server Version12.0
Mozilla ≫ Network Security Services Version3.19
Mozilla ≫ Firefox Version <= 38.1.0
Mozilla ≫ Firefox Version31.0
Mozilla ≫ Firefox Version31.1.0
Mozilla ≫ Firefox Version31.1.1
Mozilla ≫ Firefox Version31.3.0
Mozilla ≫ Firefox Version31.5.1
Mozilla ≫ Firefox Version31.5.2
Mozilla ≫ Firefox Version31.5.3
Mozilla ≫ Firefox Version38.0
Mozilla ≫ Firefox ESR Version31.1
Mozilla ≫ Firefox ESR Version31.2
Mozilla ≫ Firefox ESR Version31.3
Mozilla ≫ Firefox ESR Version31.4
Mozilla ≫ Firefox ESR Version31.5
Mozilla ≫ Firefox ESR Version31.6.0
Mozilla ≫ Firefox ESR Version31.7.0
Mozilla ≫ Thunderbird Version <= 38.0.1
Mozilla ≫ Firefox Version31.0
Mozilla ≫ Firefox Version31.1.0
Mozilla ≫ Firefox Version31.1.1
Mozilla ≫ Firefox Version31.3.0
Mozilla ≫ Firefox Version31.5.1
Mozilla ≫ Firefox Version31.5.2
Mozilla ≫ Firefox Version31.5.3
Mozilla ≫ Firefox Version38.0
Mozilla ≫ Firefox ESR Version31.1
Mozilla ≫ Firefox ESR Version31.2
Mozilla ≫ Firefox ESR Version31.3
Mozilla ≫ Firefox ESR Version31.4
Mozilla ≫ Firefox ESR Version31.5
Mozilla ≫ Firefox ESR Version31.6.0
Mozilla ≫ Firefox ESR Version31.7.0
Mozilla ≫ Thunderbird Version <= 38.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.61% | 0.691 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|