A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| mozilla | nss | 3.26 | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
99
Affected Products
18
References
mozilla / nss
| - |
| debian | debian_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| suse | linux_enterprise_server | - | - |
| avaya | aura_application_enablement_services | 6.1 - 6.3.3 | - |
| avaya | aura_application_enablement_services | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_application_server_5300 | - | - |
| avaya | aura_communication_manager | 6.0 - 6.3.117.0 | - |
| avaya | aura_communication_manager | - | - |
| avaya | aura_communication_manager | - | - |
| avaya | aura_communication_manager | - | - |
| avaya | aura_communication_manager_messagint | - | - |
| avaya | aura_communication_manager_messagint | - | - |
| avaya | breeze_platform | 3.0 - 3.2 | - |
| avaya | call_management_system | 18.0.0.1 - 18.0.0.2 | - |
| avaya | call_management_system | - | - |
| avaya | call_management_system | - | - |
| avaya | call_management_system | - | - |
| avaya | call_management_system | - | - |
| avaya | call_management_system | - | - |
| avaya | iq | - | - |
| avaya | cs1000e_firmware | 7.0 - 7.6 | - |
| avaya | cs1000m_firmware | 7.0 - 7.6 | - |
| avaya | cs1000e\/cs1000m_signaling_server_firmware | 7.0 - 7.6 | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_conferencing | - | - |
| avaya | aura_experience_portal | 6.0 - 7.1 | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | ip_office | - | - |
| avaya | aura_messaging | - | - |
| avaya | aura_messaging | - | - |
| avaya | aura_messaging | - | - |
| avaya | aura_messaging | - | - |
| avaya | aura_messaging | - | - |
| avaya | aura_session_manager | 6.3 - 6.3.18 | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_session_manager | - | - |
| avaya | aura_system_manager | 6.3 - 6.3.18 | - |
| avaya | aura_system_manager | 7.0 - 7.0.1.3 | - |
| avaya | aura_utility_services | 6.3 - 6.3.14 | - |
| avaya | aura_utility_services | 7.0 - 7.0.1.2 | - |
| avaya | meeting_exchange | - | - |
| avaya | meeting_exchange | - | - |
| avaya | message_networking | 5.2 - 6.3 | - |
| avaya | one-x_client_enablement_services | - | - |
| avaya | one-x_client_enablement_services | - | - |
| avaya | one-x_client_enablement_services | - | - |
| avaya | one-x_client_enablement_services | - | - |
| avaya | proactive_contact | 5.0 - 5.1.2 | - |
| avaya | session_border_controller_for_enterprise_firmware | 6.2 - 6.3 | - |
| avaya | session_border_controller_for_enterprise_firmware | 7.0 - 7.1 | - |
| avaya | aura_system_platform_firmware | 6.3 - 6.4.0 | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability
Impact