Nss
Vendor:
First CVE: Nov 9, 2009 · Active for 16 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nss over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 2009
16 years ago
Most Recent CVE
Dec 12, 2023
955 days ago
CVE Severity & Scoring
Nss9 CVEs
33%
22%
44%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
CVE-2021-43527CRITICAL NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS f | Dec 8, 2021 | 9.8 | 41 | NO | NO |
CVE-2019-17006CRITICAL In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a san | Oct 22, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-12403CRITICAL A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fix | May 27, 2021 | 9.1 | 28 | NO | NO |
CVE-2019-17007HIGH In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. | Oct 22, 2020 | 7.5 | 25 | NO | NO |
CVE-2016-5285HIGH A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which c | Nov 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-18508MEDIUM In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service. | Oct 22, 2020 | 6.5 | 23 | NO | NO |
CVE-2023-4421MEDIUM The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length | Dec 12, 2023 | 6.5 | 19 | NO | NO |
CVE-2016-1938MEDIUM The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which migh | Jan 31, 2016 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Nss
Top CWEs
Versions
No cataloged versions.