Lucene search

K
cvelistMozillaCVELIST:CVE-2016-5285
HistoryNov 15, 2019 - 3:44 p.m.

CVE-2016-5285

2019-11-1515:44:05
mozilla
www.cve.org
1

0.025 Low

EPSS

Percentile

90.2%

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

CNA Affected

[
  {
    "product": "Network Security Services",
    "vendor": "Mozilla",
    "versions": [
      {
        "status": "affected",
        "version": "3.24"
      }
    ]
  }
]