Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmvm-jpfj-v3f5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

EPSS

Процентиль: 74%
0.00806
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 8.1
redhat
около 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 8.8
nvd
почти 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 8.8
debian
почти 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate wa ...

oracle-oval
около 6 лет назад

ELSA-2019-4152: nss-softokn security update (IMPORTANT)

EPSS

Процентиль: 74%
0.00806
Низкий

Дефекты

CWE-787