7.5

CVE-2016-5285

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Data is provided by the National Vulnerability Database (NVD)
MozillaNss Version < 3.26
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
RedhatEnterprise Linux Version5.0
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version7.0
SuseLinux Enterprise Server Version11 Updatesp2 SwEditionltss
AvayaAura Application Enablement Services Version >= 6.1 <= 6.3.3
AvayaAura Application Server 5300 Version3.0 Update-
AvayaAura Application Server 5300 Version3.0 Updatesp1
AvayaAura Application Server 5300 Version3.0 Updatesp10
AvayaAura Application Server 5300 Version3.0 Updatesp10.1
AvayaAura Application Server 5300 Version3.0 Updatesp11
AvayaAura Application Server 5300 Version3.0 Updatesp11.1
AvayaAura Application Server 5300 Version3.0 Updatesp12
AvayaAura Application Server 5300 Version3.0 Updatesp12.1
AvayaAura Application Server 5300 Version3.0 Updatesp12.2
AvayaAura Application Server 5300 Version3.0 Updatesp12.3
AvayaAura Application Server 5300 Version3.0 Updatesp12.5
AvayaAura Application Server 5300 Version3.0 Updatesp3
AvayaAura Application Server 5300 Version3.0 Updatesp5
AvayaAura Application Server 5300 Version3.0 Updatesp7
AvayaAura Communication Manager Version >= 6.0 <= 6.3.117.0
AvayaAura Communication Manager Version7.0 Update-
AvayaAura Communication Manager Version7.0 Updatesp
AvayaAura Communication Manager Version7.0 Updatesp3
AvayaAura Communication Manager Messagint Version7.0 Updatesp1
AvayaBreeze Platform Version >= 3.0 <= 3.2
AvayaCall Management System Version >= 18.0.0.1 <= 18.0.0.2
AvayaCall Management System Version17.0 Update-
AvayaCall Management System Version17.0 Updater3
AvayaCall Management System Version17.0 Updater4
AvayaCall Management System Version17.0 Updater5
AvayaCall Management System Version17.0 Updater6
AvayaIq Version5.2.x
AvayaCs1000e Firmware Version >= 7.0 <= 7.6
   AvayaCs1000e Version-
AvayaCs1000m Firmware Version >= 7.0 <= 7.6
   AvayaCs1000m Version-
AvayaAura Conferencing Version7.0
AvayaAura Conferencing Version7.2
AvayaAura Conferencing Version8.0 Update-
AvayaAura Conferencing Version8.0 Updatesp2
AvayaAura Conferencing Version8.0 Updatesp4
AvayaAura Conferencing Version8.0 Updatesp5
AvayaAura Conferencing Version8.0 Updatesp7
AvayaAura Conferencing Version8.0 Updatesp8
AvayaAura Conferencing Version8.0 Updatesp9
AvayaAura Experience Portal Version >= 6.0 <= 7.1
AvayaIp Office Version8.1
AvayaIp Office Version9.1 Update-
AvayaIp Office Version9.1 Updatesp1
AvayaIp Office Version9.1 Updatesp10
AvayaIp Office Version9.1 Updatesp11
AvayaIp Office Version9.1 Updatesp12
AvayaIp Office Version9.1 Updatesp3
AvayaIp Office Version9.1 Updatesp4
AvayaIp Office Version9.1 Updatesp5
AvayaIp Office Version9.1 Updatesp6
AvayaIp Office Version9.1 Updatesp7
AvayaIp Office Version9.1 Updatesp8
AvayaIp Office Version9.1 Updatesp9
AvayaIp Office Version10.0 Update-
AvayaIp Office Version10.0 Updatesp1
AvayaIp Office Version10.0 Updatesp2
AvayaIp Office Version10.0 Updatesp3
AvayaIp Office Version10.0 Updatesp4
AvayaIp Office Version10.0 Updatesp5
AvayaIp Office Version10.0 Updatesp6
AvayaIp Office Version10.0 Updatesp7
AvayaAura Messaging Version6.3
AvayaAura Messaging Version6.3.3 Update-
AvayaAura Messaging Version6.3.3 Updatesp4
AvayaAura Messaging Version6.3.3 Updatesp5
AvayaAura Messaging Version6.3.3 Updatesp6
AvayaAura Session Manager Version >= 6.3 <= 6.3.18
AvayaAura Session Manager Version7.0 Update-
AvayaAura Session Manager Version7.0 Updatesp1
AvayaAura Session Manager Version7.0 Updatesp2
AvayaAura Session Manager Version7.0.1 Update-
AvayaAura Session Manager Version7.0.1 Updatesp1
AvayaAura Session Manager Version7.0.1 Updatesp2
AvayaAura System Manager Version >= 6.3 <= 6.3.18
AvayaAura System Manager Version >= 7.0 <= 7.0.1.3
AvayaAura Utility Services Version >= 6.3 <= 6.3.14
AvayaAura Utility Services Version >= 7.0 <= 7.0.1.2
AvayaMeeting Exchange Version6.2 Update-
AvayaMeeting Exchange Version6.2 Updatesp3
AvayaMessage Networking Version >= 5.2 <= 6.3
AvayaOne-x Client Enablement Services Version6.2 Update-
AvayaOne-x Client Enablement Services Version6.2 Updatesp1
AvayaOne-x Client Enablement Services Version6.2 Updatesp2
AvayaOne-x Client Enablement Services Version6.2 Updatesp5
AvayaProactive Contact Version >= 5.0 <= 5.1.2
AvayaAura System Platform Firmware Version >= 6.3 <= 6.4.0
   AvayaAura System Platform Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.65% 0.682
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.