409
VMScore

CVE-2017-11695

Published: 27/12/2017 Updated: 16/03/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent malicious users to have unspecified impact using a crafted cert8.db file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services -

Vendor Advisories

Debian Bug report logs - #873256 nss: CVE-2017-11695: heap-buffer-overflow (write of size 8) in alloc_segs Package: src:nss; Maintainer for src:nss is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 25 Aug 2017 20:51:01 UTC ...
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hashc in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8db file ...