CVEs (50)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it e...Show more |
1Mozilla 5Firefox Network Security ServicesSeamonkey+2 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x...Show more |
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows r...Show more |
3Gnu MozillaOpenssl3Gnutls Network Security ServicesOpensslApr 23, 2026 Jul 30, 2009 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise+6 moreApr 23, 2026 Jul 30, 2009 N/A· v4 5.9 MEDIUM· v3 6.8 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more |
3Canonical DebianMozilla6Debian Linux FirefoxNetwork Security Services+3 moreApr 23, 2026 Feb 26, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, a...Show more |
1Mozilla 4Firefox Network Security ServicesSeamonkey+1 moreApr 23, 2026 Feb 26, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain...Show more |
1Mozilla 4Firefox Network Security ServicesSeamonkey+1 moreApr 23, 2026 Nov 8, 2006 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly ha...Show more |
1Mozilla 4Firefox Network Security ServicesSeamonkey+1 moreApr 16, 2026 Sep 15, 2006 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly ha...Show more |
4Hp MozillaNetscape+1 more10Certificate Server Directory ServerEnterprise Server+7 moreApr 16, 2026 Dec 31, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. |