VDB
DEBIAN-CVE-2010-3173
DEBIAN-CVE-2010-3173
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | nss | 0, 0, 0 |
| Debian:11 | nss | 0, 0, 0 |
| Debian:13 | nss | 0, 0, 0 |
| Debian:12 | nss | 0, 0, 0 |
Timeline
- Oct 21, 2010 CVE Published
- Apr 28, 2026 CVE Updated