VYPR
Unrated severityNVD Advisory· Published Nov 18, 2013· Updated Jun 16, 2026

CVE-2013-5606

CVE-2013-5606

Description

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:mozilla:network_security_services:3.15:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mozilla:network_security_services:3.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:network_security_services:3.15.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:network_security_services:3.15.2:*:*:*:*:*:*:*
  • Range: >=3.15, <3.15.3

Patches

Vulnerability mechanics

References

22

News mentions

0

No linked articles in our index yet.