CVE-2014-1492
- EPSS 0.85%
- Veröffentlicht 25.03.2014 13:25:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which...
CVE-2014-1491
- EPSS 0.61%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 25.11.2025 17:50:16
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellma...
CVE-2014-1490
- EPSS 1.05%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 25.11.2025 17:50:16
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to ca...
CVE-2013-1740
- EPSS 1.05%
- Veröffentlicht 18.01.2014 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certifi...
CVE-2013-1741
- EPSS 2.6%
- Veröffentlicht 18.11.2013 05:23:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
CVE-2013-5605
- EPSS 2.79%
- Veröffentlicht 18.11.2013 05:23:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
CVE-2013-5606
- EPSS 0.66%
- Veröffentlicht 18.11.2013 05:23:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might a...
- EPSS 2.65%
- Veröffentlicht 22.10.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that t...
- EPSS 0.82%
- Veröffentlicht 03.04.2013 11:56:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other pr...
CVE-2013-1620
- EPSS 0.81%
- Veröffentlicht 08.02.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct di...