CVE-2016-2834
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu linux · opensuse/leap · opensuse/opensuse · mozilla/network security services · mozilla/firefox · novell/suse linux enterprise software development kit · novell/suse linux enterprise desktop · novell/suse linux enterprise server
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00055.html
- http://rhn.redhat.com/errata/RHSA-2016-2779.html
- http://www.debian.org/security/2016/dsa-3688
- http://www.mozilla.org/security/announce/2016/mfsa2016-61.htmlVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/91072
- http://www.securitytracker.com/id/1036057
- http://www.ubuntu.com/usn/USN-2993-1
- http://www.ubuntu.com/usn/USN-3029-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1206283Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1221620Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1241034Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1241037Issue Tracking
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.23_release_notes
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00055.html
- http://rhn.redhat.com/errata/RHSA-2016-2779.html
- http://www.debian.org/security/2016/dsa-3688
- http://www.mozilla.org/security/announce/2016/mfsa2016-61.htmlVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/91072
- http://www.securitytracker.com/id/1036057
- http://www.ubuntu.com/usn/USN-2993-1
- http://www.ubuntu.com/usn/USN-3029-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1206283Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.