CVE-2017-7502

HIGH

Network Security Services >= 3.24.0 - Denial of Service via Empty SSLv2 Message

Title source: llm
STIX 2.1

Description

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

References (9)

Core 9
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1365
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038579
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98744
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1712
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1364
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1567
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3872

Scores

CVSS v3 7.5
EPSS 0.0145
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (19)
mozilla/network_security_services 3.24.0
mozilla/network_security_services 3.25.0
mozilla/network_security_services 3.25.1
mozilla/network_security_services 3.26.0
mozilla/network_security_services 3.26.2
mozilla/network_security_services 3.27.0
mozilla/network_security_services 3.27.1
mozilla/network_security_services 3.27.2
mozilla/network_security_services 3.28.0
mozilla/network_security_services 3.28.1
... and 9 more
Published May 30, 2017
Tracked Since Feb 18, 2026