6.5
CVSSv3

CVE-2018-18508

Published: 22/10/2020 Updated: 18/02/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Network Security Services (NSS) prior to 3.36.7 and prior to 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services

siemens ruggedcom rox mx5000 firmware

siemens ruggedcom rox rx1400 firmware

siemens ruggedcom rox rx1500 firmware

siemens ruggedcom rox rx1501 firmware

siemens ruggedcom rox rx1510 firmware

siemens ruggedcom rox rx1511 firmware

siemens ruggedcom rox rx1512 firmware

siemens ruggedcom rox rx5000 firmware

Vendor Advisories

Synopsis Moderate: nss and nspr security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for nss and nspr is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Debian Bug report logs - #921614 nss: CVE-2018-18508: NULL pointer dereference in several CMS functions resulting in a denial of service Package: src:nss; Maintainer for src:nss is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
NSS could be made to crash if it received specially crafted network traffic ...
NSS could be made to crash if it received specially crafted network traffic ...