VYPR

rpm package

suse/mozilla-nss&distro=SUSE Linux Enterprise Micro 5.3

pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

Vulnerabilities (6)

  • CVE-2026-2781CriFeb 24, 2026
    affected < 3.112.3-150400.3.63.1fixed 3.112.3-150400.3.63.1

    Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35.

  • CVE-2025-9187CriAug 19, 2025
    affected < 3.112.2-150400.3.60.1fixed 3.112.2-150400.3.60.1

    Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird

  • CVE-2023-5388Mar 19, 2024
    affected < 3.101.2-150400.3.48.1fixed 3.101.2-150400.3.48.1

    NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2023-0767Jun 2, 2023
    affected < 3.79.4-150400.3.26.1fixed 3.79.4-150400.3.26.1

    An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

  • CVE-2022-23491Dec 7, 2022
    affected < 3.79.3-150400.3.23.1fixed 3.79.3-150400.3.23.1

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from

  • CVE-2022-3479Oct 14, 2022
    affected < 3.79.3-150400.3.23.1fixed 3.79.3-150400.3.23.1

    A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.