VYPR

Network Security Services (nss)

by Nss

CVEs (1)

  • CVE-2018-12384Apr 29, 2019
    risk 0.00cvss epss 0.01

    When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.