CVE-2016-5285

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
mozillanss
𝑥
< 3.26
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
redhatenterprise_linux
5.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
avayaaura_application_enablement_services
6.1 ≤
𝑥
≤ 6.3.3
avayaaura_application_enablement_services
7.0
avayaaura_application_server_5300
3.0
avayaaura_application_server_5300
3.0:sp1
avayaaura_application_server_5300
3.0:sp10
avayaaura_application_server_5300
3.0:sp10.1
avayaaura_application_server_5300
3.0:sp11
avayaaura_application_server_5300
3.0:sp11.1
avayaaura_application_server_5300
3.0:sp12
avayaaura_application_server_5300
3.0:sp12.1
avayaaura_application_server_5300
3.0:sp12.2
avayaaura_application_server_5300
3.0:sp12.3
avayaaura_application_server_5300
3.0:sp12.5
avayaaura_application_server_5300
3.0:sp3
avayaaura_application_server_5300
3.0:sp5
avayaaura_application_server_5300
3.0:sp7
avayaaura_communication_manager
6.0 ≤
𝑥
≤ 6.3.117.0
avayaaura_communication_manager
7.0
avayaaura_communication_manager
7.0:sp
avayaaura_communication_manager
7.0:sp3
avayaaura_communication_manager_messagint
7.0
avayaaura_communication_manager_messagint
7.0:sp1
avayabreeze_platform
3.0 ≤
𝑥
≤ 3.2
avayacall_management_system
18.0.0.1 ≤
𝑥
≤ 18.0.0.2
avayacall_management_system
17.0
avayacall_management_system
17.0:r3
avayacall_management_system
17.0:r4
avayacall_management_system
17.0:r5
avayacall_management_system
17.0:r6
avayaiq
5.2.x:x
avayacs1000e_firmware
7.0 ≤
𝑥
≤ 7.6
avayacs1000m_firmware
7.0 ≤
𝑥
≤ 7.6
avayacs1000e\/cs1000m_signaling_server_firmware
7.0 ≤
𝑥
≤ 7.6
avayaaura_conferencing
7.0
avayaaura_conferencing
7.2
avayaaura_conferencing
8.0
avayaaura_conferencing
8.0:sp2
avayaaura_conferencing
8.0:sp4
avayaaura_conferencing
8.0:sp5
avayaaura_conferencing
8.0:sp7
avayaaura_conferencing
8.0:sp8
avayaaura_conferencing
8.0:sp9
avayaaura_experience_portal
6.0 ≤
𝑥
≤ 7.1
avayaip_office
8.1
avayaip_office
9.1
avayaip_office
9.1:sp1
avayaip_office
9.1:sp10
avayaip_office
9.1:sp11
avayaip_office
9.1:sp12
avayaip_office
9.1:sp3
avayaip_office
9.1:sp4
avayaip_office
9.1:sp5
avayaip_office
9.1:sp6
avayaip_office
9.1:sp7
avayaip_office
9.1:sp8
avayaip_office
9.1:sp9
avayaip_office
10.0
avayaip_office
10.0:sp1
avayaip_office
10.0:sp2
avayaip_office
10.0:sp3
avayaip_office
10.0:sp4
avayaip_office
10.0:sp5
avayaip_office
10.0:sp6
avayaip_office
10.0:sp7
avayaaura_messaging
6.3
avayaaura_messaging
6.3.3
avayaaura_messaging
6.3.3:sp4
avayaaura_messaging
6.3.3:sp5
avayaaura_messaging
6.3.3:sp6
avayaaura_session_manager
6.3 ≤
𝑥
≤ 6.3.18
avayaaura_session_manager
7.0
avayaaura_session_manager
7.0:sp1
avayaaura_session_manager
7.0:sp2
avayaaura_session_manager
7.0.1
avayaaura_session_manager
7.0.1:sp1
avayaaura_session_manager
7.0.1:sp2
avayaaura_system_manager
6.3 ≤
𝑥
≤ 6.3.18
avayaaura_system_manager
7.0 ≤
𝑥
≤ 7.0.1.3
avayaaura_utility_services
6.3 ≤
𝑥
≤ 6.3.14
avayaaura_utility_services
7.0 ≤
𝑥
≤ 7.0.1.2
avayameeting_exchange
6.2
avayameeting_exchange
6.2:sp3
avayamessage_networking
5.2 ≤
𝑥
≤ 6.3
avayaone-x_client_enablement_services
6.2
avayaone-x_client_enablement_services
6.2:sp1
avayaone-x_client_enablement_services
6.2:sp2
avayaone-x_client_enablement_services
6.2:sp5
avayaproactive_contact
5.0 ≤
𝑥
≤ 5.1.2
avayasession_border_controller_for_enterprise_firmware
6.2 ≤
𝑥
≤ 6.3
avayasession_border_controller_for_enterprise_firmware
7.0 ≤
𝑥
≤ 7.1
avayaaura_system_platform_firmware
6.3 ≤
𝑥
≤ 6.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nss
zesty
not-affected
yakkety
not-affected
xenial
Fixed 2:3.26.2-0ubuntu0.16.04.2
released
trusty
Fixed 2:3.26.2-0ubuntu0.14.04.3
released
precise
Fixed 2:3.26.2-0ubuntu0.12.04.1
released