4.3
CVSSv2

CVE-2011-5094

Published: 16/06/2012 Updated: 11/04/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote malicious users to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services 3.11.2

mozilla network security services 3.6.1

mozilla network security services 3.2

mozilla network security services 3.11.4

mozilla network security services 3.7.7

mozilla network security services 3.7.5

mozilla network security services 3.7.1

mozilla network security services 3.6

mozilla network security services 3.2.1

mozilla network security services 3.9

mozilla network security services 3.4

mozilla network security services 3.8

mozilla network security services 3.4.1

mozilla network security services 3.11.5

mozilla network security services 3.7

mozilla network security services 3.7.2

mozilla network security services 3.3

mozilla network security services 3.7.3

mozilla network security services 3.4.2

mozilla network security services 3.3.2

mozilla network security services 3.5

mozilla network security services 3.11.3

mozilla network security services 3.3.1