Name
nss
Version
3.98
Type
library
Description
Mozilla's SSL and TLS implementation
Licenses
(MPL-2.0 & MIT) | (MPL-2.0 & GPL-2.0-or-later & MIT) | (MPL-2.0 & LGPL-2.1-or-later & MIT)
PURL
-
CPE
cpe:2.3:*:*:network_security_services:3.98:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
nss: fix incorrect shebang of perl
Ovidiu Panait <ovidiu.panait@windriver.com>
2
nss,nspr: Add recipes
Khem Raj <raj.khem@gmail.com>
3
nss:no rpath for cross compiling
Hongxu Jia <hongxu.jia@windriver.com>
4
nss does not build on mips with clang because wrong types are
Khem Raj <raj.khem@gmail.com>
5
Bug 1895032 - remove redundant AllocItem implementation.
John Schanck <jschanck@mozilla.com>
CVE-2024-6602
6
Fix nss multilib build on openSUSE 11.x 32bit
Wenzong Fan <wenzong.fan@windriver.com>
7
Bug 2009552 - avoid integer overflow in platform-independent
John Schanck <jschanck@mozilla.com>
CVE-2026-2781
8
freebl: add a configure option to disable ARM HW crypto
Alexander Kanavin <alex.kanavin@gmail.com>
9
fix CVE-2024-6609
Peter Marko <peter.marko@siemens.com>
CVE-2024-6609
10
nss: fix support cross compiling
Alexander Kanavin <alex.kanavin@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Patched
Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35.
Patched
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Patched
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
False Positive
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
False Positive
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
False Positive
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
False Positive
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
False Positive
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.