4.3

CVE-2015-2730

Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
NovellSuse Linux Enterprise Server Version11 Updatesp4
MozillaNetwork Security Services Version <= 3.19
   MozillaFirefox Version <= 38.1.0
   MozillaFirefox Version31.0
   MozillaFirefox Version31.1.0
   MozillaFirefox Version31.1.1
   MozillaFirefox Version31.3.0
   MozillaFirefox Version31.5.1
   MozillaFirefox Version31.5.2
   MozillaFirefox Version31.5.3
   MozillaFirefox Version38.0
   MozillaFirefox ESR Version31.1
   MozillaFirefox ESR Version31.2
   MozillaFirefox ESR Version31.3
   MozillaFirefox ESR Version31.4
   MozillaFirefox ESR Version31.5
   MozillaFirefox ESR Version31.6.0
   MozillaFirefox ESR Version31.7.0
OracleSolaris Version11.3
OracleVm Server Version3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.56
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N