← Back

CVE-2014-1568

nvd nist
Published: Sep 25, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

Affected (230)

1 product
Chrome
5 products
Firefox
Firefox Esr
Network Security Services
Seamonkey
Thunderbird
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 37.0.2062.120
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Microsoft
Windows
All versions
Configuration B
223 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 32.0
Version 31.0
Version 31.1.0
Version 32.0.1
Version 32.0.2
Version 24.8.0
Mozilla
Up to 3.16.2.0
Version 3.11.2
Version 3.11.3
Version 3.11.4
Version 3.11.5
Version 3.12.10
Version 3.12.11
Version 3.12.1
Version 3.12.2
Version 3.12.3.1
Version 3.12.3.2
Version 3.12.3
Version 3.12.4
Version 3.12.5
Version 3.12.6
Version 3.12.7
Version 3.12.8
Version 3.12.9
Version 3.12
Version 3.14.1
Version 3.14.2
Version 3.14.3
Version 3.14.4
Version 3.14.5
Version 3.14
Version 3.15.1
Version 3.15.2
Version 3.15.3.1
Version 3.15.3
Version 3.15.4
Version 3.15.5
Version 3.15
Version 3.16.1
Version 3.16.3
Version 3.16.4
Version 3.16
Version 3.2.1
Version 3.2
Version 3.3.1
Version 3.3.2
Version 3.3
Version 3.4.1
Version 3.4.2
Version 3.4
Version 3.5
Version 3.6.1
Version 3.6
Version 3.7.1
Version 3.7.2
Version 3.7.3
Version 3.7.5
Version 3.7.7
Version 3.7
Version 3.8
Version 3.9
Mozilla
All versions
Up to 2.29
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.0
Version 1.0 alpha
Version 1.0 beta
Version 1.1.10
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16
Version 1.1.17
Version 1.1.18
Version 1.1.19
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9
Version 1.1
Version 1.1 alpha
Version 1.1 beta
Version 1.5.0.10
Version 1.5.0.8
Version 1.5.0.9
Version 2.0.10
Version 2.0.11
Version 2.0.12
Version 2.0.13
Version 2.0.14
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.0
Version 2.0 alpha_1
Version 2.0 alpha_2
Version 2.0 alpha_3
Version 2.0 beta_1
Version 2.0 beta_2
Version 2.0 rc1
Version 2.0 rc2
Version 2.10.1
Version 2.10
Version 2.10 beta1
Version 2.10 beta2
Version 2.10 beta3
Version 2.11
Version 2.11 beta1
Version 2.11 beta2
Version 2.11 beta3
Version 2.11 beta4
Version 2.11 beta5
Version 2.11 beta6
Version 2.12.1
Version 2.12
Version 2.12 beta1
Version 2.12 beta2
Version 2.12 beta3
Version 2.12 beta4
Version 2.12 beta5
Version 2.12 beta6
Version 2.13.1
Version 2.13.2
Version 2.13
Version 2.13 beta1
Version 2.13 beta2
Version 2.13 beta3
Version 2.13 beta4
Version 2.13 beta5
Version 2.13 beta6
Version 2.14
Version 2.14 beta1
Version 2.14 beta2
Version 2.14 beta3
Version 2.14 beta4
Version 2.14 beta5
Version 2.15.1
Version 2.15.2
Version 2.15
Version 2.15 beta1
Version 2.15 beta2
Version 2.15 beta3
Version 2.15 beta4
Version 2.15 beta5
Version 2.15 beta6
Version 2.16.1
Version 2.16.2
Version 2.16
Version 2.16 beta1
Version 2.16 beta2
Version 2.16 beta3
Version 2.16 beta4
Version 2.16 beta5
Version 2.17.1
Version 2.17
Version 2.17 beta1
Version 2.17 beta2
Version 2.17 beta3
Version 2.17 beta4
Version 2.18 beta1
Version 2.18 beta2
Version 2.18 beta3
Version 2.18 beta4
Version 2.19
Version 2.19 beta1
Version 2.19 beta2
Version 2.1
Version 2.1 alpha1
Version 2.1 alpha2
Version 2.1 alpha3
Version 2.1 beta1
Version 2.1 beta2
Version 2.1 beta3
Version 2.1 rc1
Version 2.1 rc2
Version 2.20
Version 2.20 beta1
Version 2.20 beta2
Version 2.20 beta3
Version 2.21 beta1
Version 2.21 beta2
Version 2.22.1
Version 2.22 beta1
Version 2.22 beta2
Version 2.23
Version 2.23 beta1
Version 2.24
Version 2.24 beta1
Version 2.25
Version 2.25 beta1
Version 2.25 beta2
Version 2.25 beta3
Version 2.26
Version 2.26 rc1
Version 2.2
Version 2.2 beta1
Version 2.2 beta2
Version 2.2 beta3
Mozilla
Up to 24.8.0
Version 31.0
Version 31.1.0
Version 31.1.1
Configuration C
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Google
Up to 37.0.2062.103
Version 37.0.2062.0
Version 37.0.2062.100
Version 37.0.2062.102
Version 37.0.2062.20
Version 37.0.2062.3
Running on/withPlatform Versions
Google
Chrome Os
All versions

Related CWEs

References (68)

Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
US Government Resource
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.