peter bassill · operator
$ cve CVE-2019-17006 JSON

CVE-2019-17006

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.56% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-10-22
Last modified2026-06-17

Affected (21)

VendorProduct
mozillanetwork security services
netapphci compute node
netapphci management node
netapphci storage node
netappsolidfire
siemensruggedcom rox mx5000
siemensruggedcom rox mx5000 firmware
siemensruggedcom rox rx1400
siemensruggedcom rox rx1400 firmware
siemensruggedcom rox rx1500
siemensruggedcom rox rx1500 firmware
siemensruggedcom rox rx1501
siemensruggedcom rox rx1501 firmware
siemensruggedcom rox rx1510
siemensruggedcom rox rx1510 firmware
siemensruggedcom rox rx1511
siemensruggedcom rox rx1511 firmware
siemensruggedcom rox rx1512
siemensruggedcom rox rx1512 firmware
siemensruggedcom rox rx5000
siemensruggedcom rox rx5000 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD