CVE-2017-11696 PUBLISHED

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

EPSS 0.09% · 25.2th percentile

Risk Scores

EPSS Score
0.09%
25.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSnss0, 2:3.15.1-1ubuntu1, 2:3.15.2-1
Ubuntu:Pro:16.04:LTSnss0, 2:3.19.2-1ubuntu1, 2:3.19.2.1-0ubuntu1
Ubuntu:18.04:LTSnss0, 2:3.32-1ubuntu3, 2:3.34-1ubuntu1

Timeline

References

Open in Interactive Console →