CVE-2015-7575
- EPSS 1.69%
- Veröffentlicht 09.01.2016 02:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it e...
CVE-2015-7183
- EPSS 18.19%
- Veröffentlicht 05.11.2015 05:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and othe...
CVE-2015-7182
- EPSS 21.71%
- Veröffentlicht 05.11.2015 05:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause ...
CVE-2015-7181
- EPSS 22.25%
- Veröffentlicht 05.11.2015 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified d...
CVE-2015-2730
- EPSS 0.24%
- Veröffentlicht 06.07.2015 02:01:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which...
CVE-2015-2721
- EPSS 0.61%
- Veröffentlicht 06.07.2015 02:00:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS sta...
CVE-2015-4000
- EPSS 93.9%
- Veröffentlicht 21.05.2015 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a Clie...
CVE-2014-1569
- EPSS 3.64%
- Veröffentlicht 15.12.2014 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers...
CVE-2014-1568
- EPSS 35.83%
- Veröffentlicht 25.09.2014 17:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31...
- EPSS 3.22%
- Veröffentlicht 23.07.2014 11:12:42
- Zuletzt bearbeitet 25.11.2025 17:50:16
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to e...