5.9
CVSSv3

CVE-2016-8635

Published: 01/08/2018 Updated: 12/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

It exists that NSS incorrectly handled certain invalid Diffie-Hellman keys. A remote attacker could possibly use this flaw to cause NSS to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5285)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services

redhat enterprise linux desktop 7.0

redhat enterprise linux server 5.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux workstation 5.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server tus 7.3

redhat enterprise linux desktop 5.0

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

redhat enterprise linux server tus 7.6

redhat enterprise linux server eus 7.6

redhat enterprise linux server aus 7.6

Vendor Advisories

Synopsis Moderate: nss and nss-util security update Type/Severity Security Advisory: Moderate Topic An update for nss and nss-util is now available for Red Hat Enterprise Linux 5,Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security im ...
Several security issues were fixed in NSS ...
CVE-2016-2834 nss: Multiple security flaws (MFSA 2016-61)Multiple buffer handling flaws were found in the way NSS handled cryptographic data from the network A remote attacker could use these flaws to crash an application using NSS or, possibly, execute arbitrary code with the permission of the user running the application CVE-2016-8635 nss: smal ...
It was found that Diffie Hellman Client key exchange handling in NSS was vulnerable to small subgroup confinement attack An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group ...