4.6
CVSSv2

CVE-2017-11697

Published: 27/12/2017 Updated: 16/03/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent malicious users to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services -

Vendor Advisories

Debian Bug report logs - #873258 nss: CVE-2017-11697: Floating Point Exception in __hash_open (hashc:229) Package: src:nss; Maintainer for src:nss is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 25 Aug 2017 20:54:04 UTC ...
The __hash_open function in hashc:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8db file ...