ZeroHour

CVE-2016-5285

CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Vendors
mozilladebianredhatsuseavaya
Products
nss, debian linux, enterprise linux, linux enterprise server, aura application enablement services, aura application server 5300, aura communication manager, aura communication manager messagint, breeze platform, call management system, iq, cs1000e firmware
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.