CVE-2023-4421
- EPSS 0.22%
- Veröffentlicht 12.12.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:35:06
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By ...
CVE-2021-43527
- EPSS 5.24%
- Veröffentlicht 08.12.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:29:21
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \...
CVE-2020-12403
- EPSS 0.19%
- Veröffentlicht 27.05.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 04:59:38
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not function...
CVE-2016-5285
- EPSS 0.65%
- Veröffentlicht 15.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:53:59
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
CVE-2016-1938
- EPSS 1.05%
- Veröffentlicht 31.01.2016 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protecti...
CVE-2009-3555
- EPSS 2.84%
- Veröffentlicht 09.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...