CVE-2016-1979

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/03/2016
Last modified:
12/04/2025

Description

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 44.0.2 (including)
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* 3.21 (including)


References to Advisories, Solutions, and Tools