Known vulnerabilities in nss (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:nss_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 7
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nss (Ubuntu package) nss (Ubuntu package) is affected by 7 known vulnerabilities: 1 high, 2 medium, 4 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134640 - Memory corruption
CVE-2026-12318
CWE-119 Low
No
No
2:3.98-0ubuntu0.22.04.4, 2:3.98-1ubuntu0.2, 2:3.114-1ubuntu0.2, 2:3.120-1ubuntu2.1 16.06.2026 SB2026061653
SB2026061757
SB2026070132
#VU123207 - Integer overflow
CVE-2026-2781
CWE-190 Low
No
No
2:3.28.4-0ubuntu0.14.04.5+esm13, 2:3.28.4-0ubuntu0.16.04.14+esm5, 2:3.35-2ubuntu2.16+esm1, 2:3.98-0ubuntu0.20.04.2+esm1, 2:3.98-0ubuntu0.22.04.3, 2:3.98-1ubuntu0.1, 2:3.114-1ubuntu0.1 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 43 more
#VU23467 - Improper input validation
CVE-2019-17007
CWE-20 Medium
No
No
2:3.28.4-0ubuntu0.16.04.9, 2:3.35-2ubuntu2.6, 2:3.42-1ubuntu2.4 09.12.2019 SB2019112801
SB2019120912
SB2019120913
and 4 more
#VU23050 - Out-of-bounds write
CVE-2019-11745
CWE-787 High
No
No
2:3.28.4-0ubuntu0.16.04.8, 2:3.35-2ubuntu2.5, 2:3.42-1ubuntu2.3, 2:3.45-1ubuntu2.1 28.11.2019 SB2019112801
SB2019112802
SB2019120312
and 29 more
#VU16219 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2018-12404
CWE-300 Medium
No
No
- 04.12.2018 SB2018120401
SB2018120402
SB2018121303
and 14 more
#VU15735 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2018-12384
CWE-300 Low
No
No
- 06.11.2018 SB2018110608
SB2018121303
SB2018123004
and 11 more
#VU13370 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0495
CWE-200 Low
Available
No
- 16.06.2018 SB2018061705
SB2018061412
SB2018061801
and 22 more