CVE-2011-5094
- EPSS 3.44%
- Veröffentlicht 16.06.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to ...
- EPSS 3.79%
- Veröffentlicht 05.06.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey b...
CVE-2009-2404
- EPSS 21.02%
- Veröffentlicht 03.08.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a d...
CVE-2009-2409
- EPSS 2.24%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificat...
CVE-2009-2408
- EPSS 1.69%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2007-0009
- EPSS 49.54%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System ser...
CVE-2007-0008
- EPSS 17.42%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server produc...
CVE-2006-5462
- EPSS 12.79%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature...
- EPSS 4.51%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature...
CVE-2004-0826
- EPSS 3%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.