← Back

CVE-2016-5285

nvd nist
Published: Nov 15, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Affected (99)

Products: Mozilla: Nss · Debian: Debian Linux · Redhat: Enterprise Linux · +2 more
Show all products
1 product
Nss
1 product
Debian Linux
1 product
Enterprise Linux
1 product
Linux Enterprise Server
23 products
Aura Application Server 5300
Aura Communication Manager
Breeze Platform
Call Management System
Iq
Cs1000e Firmware
Cs1000m Firmware
Aura Conferencing
Aura Experience Portal
Ip Office
Aura Messaging
Aura Session Manager
Aura System Manager
Aura Utility Services
Meeting Exchange
Message Networking
One X Client Enablement Services
Proactive Contact
Aura System Platform Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.26
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 5.0
Version 6.0
Version 7.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11 sp2
Configuration E
30 vulnerable
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 7.0 to 7.6
Running on/withPlatform Versions
Avaya
Cs1000e
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 7.0 to 7.6
Running on/withPlatform Versions
Avaya
Cs1000m
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 7.0 to 7.6
Running on/withPlatform Versions
Avaya
Cs1000e/cs1000m Signaling Server
All versions
Configuration I
10 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
Version 7.0
Version 7.2
Version 8.0
Version 8.0 sp2
Version 8.0 sp4
Version 8.0 sp5
Version 8.0 sp7
Version 8.0 sp8
Version 8.0 sp9
From 6.0 to 7.1
Configuration J
21 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
Version 10.0
Version 10.0 sp1
Version 10.0 sp2
Version 10.0 sp3
Version 10.0 sp4
Version 10.0 sp5
Version 10.0 sp6
Version 10.0 sp7
Version 8.1
Version 9.1
Version 9.1 sp10
Version 9.1 sp11
Version 9.1 sp12
Version 9.1 sp1
Version 9.1 sp3
Version 9.1 sp4
Version 9.1 sp5
Version 9.1 sp6
Version 9.1 sp7
Version 9.1 sp8
Version 9.1 sp9
Configuration K
24 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
Version 6.3.3
Version 6.3.3 sp4
Version 6.3.3 sp5
Version 6.3.3 sp6
Version 6.3
Avaya
From 6.3 to 6.3.18
Version 7.0.1
Version 7.0.1 sp1
Version 7.0.1 sp2
Version 7.0
Version 7.0 sp1
Version 7.0 sp2
Avaya
From 6.3 to 6.3.18
From 7.0 to 7.0.1.3
Avaya
From 6.3 to 6.3.14
From 7.0 to 7.0.1.2
Avaya
Version 6.2
Version 6.2 sp3
From 5.2 to 6.3
Avaya
Version 6.2
Version 6.2 sp1
Version 6.2 sp2
Version 6.2 sp5
From 5.0 to 5.1.2
Configuration L
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Avaya
From 6.2 to 6.3
From 7.0 to 7.1
Running on/withPlatform Versions
Avaya
Session Border Controller For Enterprise
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 6.3 to 6.4.0
Running on/withPlatform Versions
Avaya
Aura System Platform
All versions

References (18)

Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.