CVE-2019-17006
22.10.2020, 21:15
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | ruggedcom_rox_mx5000_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1400_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1500_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1501_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1510_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1511_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx1512_firmware | 𝑥 < 2.14.0 |
siemens | ruggedcom_rox_rx5000_firmware | 𝑥 < 2.14.0 |
mozilla | network_security_services | 𝑥 < 3.46 |
netapp | hci_management_node | - |
netapp | solidfire | - |
netapp | hci_compute_node | - |
netapp | hci_storage_node | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References