CVE-2015-2730

EUVD-2015-2820
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
novellsuse_linux_enterprise_software_development_kit
12.0
debiandebian_linux
7.0
debiandebian_linux
8.0
novellsuse_linux_enterprise_desktop
12.0
novellsuse_linux_enterprise_server
12.0
mozillanetwork_security_services
𝑥
≤ 3.19
oraclesolaris
11.3
oraclevm_server
3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bookworm
2:3.87.1-1
fixed
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
jessie
not-affected
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 39.0+build5-0ubuntu0.12.04.2
released
trusty
Fixed 39.0+build5-0ubuntu0.14.04.1
released
utopic
Fixed 39.0+build5-0ubuntu0.14.10.1
released
vivid
Fixed 39.0+build5-0ubuntu0.15.04.1
released
nss
precise
Fixed 3.19.2-0ubuntu0.12.04.1
released
trusty
Fixed 2:3.19.2-0ubuntu0.14.04.1
released
utopic
Fixed 2:3.19.2-0ubuntu0.14.10.1
released
vivid
Fixed 2:3.19.2-0ubuntu15.04.1
released
thunderbird
precise
Fixed 1:31.8.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 1:31.8.0+build1-0ubuntu0.14.04.1
released
utopic
Fixed 1:31.8.0+build1-0ubuntu0.14.10.1
released
vivid
Fixed 1:31.8.0+build1-0ubuntu0.15.04.1
released
Common Weakness Enumeration
References