Known vulnerabilities in nss (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:nss_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 20
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nss (Red Hat package) nss (Red Hat package) is affected by 20 known vulnerabilities: 4 high, 10 medium, 6 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85267 - Covert Timing Channel
CVE-2023-5388
CWE-385 Medium
No
No
3.79.0-12.el8_6, 3.90.0-4.el8_8, 3.90.0-4.el8_9, 3.90.0-4.el9_2 10.01.2024 SB2024011031
SB2024011042
SB2024011043
and 96 more
#VU84568 - Observable discrepancy
CVE-2023-6135
CWE-203 Medium
No
No
3.90.0-6.el8_8, 3.90.0-6.el8_9, 3.90.0-6.el9_2, 3.90.0-6.el9_3 19.12.2023 SB2023121946
SB2023122118
SB2024010201
and 33 more
#VU82285 - Resource exhaustion
CVE-2016-1978
CWE-400 Medium
No
No
3.21.0-6.el5_11 20.10.2023 SB2016050808
SB2016042119
SB2016042506
#VU72250 - Out-of-bounds write
CVE-2023-0767
CWE-787 Medium
No
No
3.44.0-11.el8_1, 3.44.0-13.el6_10, 3.53.1-13.el8_2, 3.67.0-8.el8_4, 3.79.0-5.el7_9, 3.79.0-11.el8_6, 3.79.0-11.el8_7, 3.79.0-17.el9_0, 3.79.0-17.el9_1 15.02.2023 SB2023021549
SB2023021551
SB2023021552
and 84 more
#VU58477 - Heap-based Buffer Overflow
CVE-2021-43527
CWE-122 High
No
No
3.28.4-2.el7_3, 3.28.4-18.el7_4, 3.36.0-10.2.el7_6, 3.44.0-8.el7_7, 3.44.0-10.el8_1, 3.44.0-12.el6_10, 3.53.1-12.el8_2, 3.67.0-4.el7_9, 3.67.0-7.el8_4, 3.67.0-7.el8_5 01.12.2021 SB2021120123
SB2021120124
SB2021120201
and 66 more
#VU47910 - Allocation of Resources Without Limits or Throttling
CVE-2020-25648
CWE-770 Medium
No
No
3.53.1-7.el7_9, 3.67.0-6.el8_4 21.10.2020 SB2020102132
SB2020102609
SB2021050605
and 18 more
#VU47197 - Heap-based Buffer Overflow
CVE-2019-17006
CWE-122 High
No
No
3.36.0-9.el7_6, 3.53.1-3.el7_9, 3.53.1-11.el8_2 30.09.2020 SB2019090221
SB2020093089
SB2020062437
and 19 more
#VU46019 - Cryptographic Issues
CVE-2020-6829
CWE-310 Low
No
No
3.53.1-3.el7_9, 3.53.1-17.el8_3 25.08.2020 SB2020082520
SB2020072974
SB2020072975
and 18 more
#VU45799 - Out-of-bounds read
CVE-2020-12403
CWE-125 Medium
No
No
3.36.0-9.el7_6, 3.53.1-3.el7_9, 3.53.1-17.el8_3 20.08.2020 SB2020082004
SB2020082005
SB2020072966
and 17 more
#VU45798 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-12401
CWE-327 Low
No
No
3.53.1-3.el7_9 20.08.2020 SB2020082004
SB2020082005
SB2020072965
and 19 more
#VU45797 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-12400
CWE-327 Low
No
No
3.53.1-3.el7_9, 3.53.1-17.el8_3 20.08.2020 SB2020082004
SB2020082005
SB2020072964
and 19 more
#VU29460 - Cryptographic Issues
CVE-2020-12402
CWE-310 Low
No
No
3.53.1-3.el7_9, 3.53.1-11.el8_2 02.07.2020 SB2020070208
SB2020071322
SB2020071401
and 23 more
#VU26105 - NULL Pointer Dereference
CVE-2018-18508
CWE-476 Low
No
No
3.44.0-7.el8_0 17.03.2020 SB2020031706
SB2020011201
SB2021022218
and 3 more
#VU24061 - Selection of Less-Secure Algorithm During Negotiat
CVE-2019-17023
CWE-757 Low
No
No
3.53.1-3.el7_9, 3.53.1-11.el8_2 07.01.2020 SB2020010708
SB2020010807
SB2020010712
and 13 more
#VU23562 - Improper input validation
CVE-2019-11729
CWE-20 Medium
No
No
3.44.0-7.el8_0 12.12.2019 SB2019062813
SB2019121210
SB2020031903
and 11 more
#VU23467 - Improper input validation
CVE-2019-17007
CWE-20 Medium
No
No
3.36.0-9.el7_6 09.12.2019 SB2019112801
SB2019120912
SB2019120913
and 4 more
#VU23369 - Use After Free
CVE-2019-11756
CWE-416 High
No
No
3.36.0-9.el7_6, 3.53.1-3.el7_9, 3.53.1-11.el8_2 03.12.2019 SB2019120312
SB2019120314
SB2019121002
and 16 more
#VU33037 - Out-of-bounds read
CVE-2019-11719
CWE-125 Medium
No
No
3.44.0-7.el8_0, 3.53.1-3.el7_9 23.07.2019 SB2019072322
SB2019082322
SB2019073024
and 17 more
#VU47195 - Improper Certificate Validation
CVE-2019-11727
CWE-295 Medium
No
No
3.44.0-7.el8_0, 3.53.1-3.el7_9 23.07.2019 SB2020093089
SB2020011201
SB2021043017
and 8 more
#VU33635 - Improper input validation
CVE-2016-1979
CWE-20 High
No
No
3.21.0-6.el5_11 13.03.2016 SB2016032406
SB2016042506