Vulnerabilities
Vulnerable Software
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
CVSS Score
9.8
EPSS Score
0.031
Published
2020-10-22
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-10-22
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-10-20


Contact Us

Shodan ® - All rights reserved