[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2016-1950

Date: (C)2016-04-28   (M)2017-12-01 


Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.

CVSS Score: 6.8Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
SECTRACK-1035215
BID-84223
APPLE-SA-2016-03-21-1
APPLE-SA-2016-03-21-2
APPLE-SA-2016-03-21-3
APPLE-SA-2016-03-21-5
DSA-3510
DSA-3520
DSA-3688
GLSA-201605-06
RHSA-2016:0495
SUSE-SU-2016:0727
SUSE-SU-2016:0777
SUSE-SU-2016:0820
SUSE-SU-2016:0909
USN-2917-1
USN-2917-2
USN-2917-3
USN-2924-1
USN-2934-1
http://www.mozilla.org/security/announce/2016/mfsa2016-35.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
https://bto.bluecoat.com/security-advisory/sa119
https://bugzilla.mozilla.org/show_bug.cgi?id=1245528
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.3_release_notes
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_notes
https://support.apple.com/HT206166
https://support.apple.com/HT206167
https://support.apple.com/HT206168
https://support.apple.com/HT206169
openSUSE-SU-2016:0731
openSUSE-SU-2016:0733
openSUSE-SU-2016:1557

CPE    27
cpe:/o:novell:opensuse:13.1
cpe:/o:oracle:linux:7.0
cpe:/o:oracle:linux:6.0
cpe:/a:oracle:glassfish_server:2.1.1
...
CWE    1
CWE-119
OVAL    23
oval:org.secpod.oval:def:33467
oval:org.secpod.oval:def:1600399
oval:org.secpod.oval:def:1501384
oval:org.secpod.oval:def:501777
...

© 2013 SecPod Technologies