CVE-2015-2730

Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
novellsuse_linux_enterprise_software_development_kit
12.0
debiandebian_linux
7.0
debiandebian_linux
8.0
novellsuse_linux_enterprise_desktop
12.0
novellsuse_linux_enterprise_server
12.0
mozillanetwork_security_services
𝑥
≤ 3.19
oraclesolaris
11.3
oraclevm_server
3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
jessie
not-affected
wheezy
not-affected
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
vivid
Fixed 39.0+build5-0ubuntu0.15.04.1
released
utopic
Fixed 39.0+build5-0ubuntu0.14.10.1
released
trusty
Fixed 39.0+build5-0ubuntu0.14.04.1
released
precise
Fixed 39.0+build5-0ubuntu0.12.04.2
released
nss
vivid
Fixed 2:3.19.2-0ubuntu15.04.1
released
utopic
Fixed 2:3.19.2-0ubuntu0.14.10.1
released
trusty
Fixed 2:3.19.2-0ubuntu0.14.04.1
released
precise
Fixed 3.19.2-0ubuntu0.12.04.1
released
thunderbird
vivid
Fixed 1:31.8.0+build1-0ubuntu0.15.04.1
released
utopic
Fixed 1:31.8.0+build1-0ubuntu0.14.10.1
released
trusty
Fixed 1:31.8.0+build1-0ubuntu0.14.04.1
released
precise
Fixed 1:31.8.0+build1-0ubuntu0.12.04.1
released
Common Weakness Enumeration
References