CVE
- Id
- 88797
- CVE No.
- CVE-2016-1978
- Status
- Candidate
- Description
- Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
- Phase
- Assigned (20160120)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 772024 | 88797 | CVE-2016-1978 | MISC:https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21_release_notes | View |
| 772025 | 88797 | CVE-2016-1978 | CONFIRM:http://www.mozilla.org/security/announce/2016/mfsa2016-15.html | View |
| 772026 | 88797 | CVE-2016-1978 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=1209546 | View |
| 772027 | 88797 | CVE-2016-1978 | CONFIRM:https://bto.bluecoat.com/security-advisory/sa124 | View |
| 772028 | 88797 | CVE-2016-1978 | CONFIRM:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | View |
| 772029 | 88797 | CVE-2016-1978 | CONFIRM:http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | View |
| 772030 | 88797 | CVE-2016-1978 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | View |
| 772031 | 88797 | CVE-2016-1978 | GENTOO:GLSA-201605-06 | View |
| 772032 | 88797 | CVE-2016-1978 | URL:https://security.gentoo.org/glsa/201605-06 | View |
| 772033 | 88797 | CVE-2016-1978 | REDHAT:RHSA-2016:0591 | View |
| 772034 | 88797 | CVE-2016-1978 | URL:http://rhn.redhat.com/errata/RHSA-2016-0591.html | View |
| 772035 | 88797 | CVE-2016-1978 | REDHAT:RHSA-2016:0684 | View |
| 772036 | 88797 | CVE-2016-1978 | URL:http://rhn.redhat.com/errata/RHSA-2016-0684.html | View |
| 772037 | 88797 | CVE-2016-1978 | REDHAT:RHSA-2016:0685 | View |
| 772038 | 88797 | CVE-2016-1978 | URL:http://rhn.redhat.com/errata/RHSA-2016-0685.html | View |
| 772039 | 88797 | CVE-2016-1978 | SUSE:SUSE-SU-2016:0909 | View |
| 772040 | 88797 | CVE-2016-1978 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html | View |
| 772041 | 88797 | CVE-2016-1978 | SUSE:SUSE-SU-2016:0727 | View |
| 772042 | 88797 | CVE-2016-1978 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html | View |
| 772043 | 88797 | CVE-2016-1978 | SUSE:SUSE-SU-2016:0777 | View |
| 772044 | 88797 | CVE-2016-1978 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html | View |
| 772045 | 88797 | CVE-2016-1978 | SUSE:SUSE-SU-2016:0820 | View |
| 772046 | 88797 | CVE-2016-1978 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.html | View |
| 772047 | 88797 | CVE-2016-1978 | UBUNTU:USN-2973-1 | View |
| 772048 | 88797 | CVE-2016-1978 | URL:http://www.ubuntu.com/usn/USN-2973-1 | View |
| 772049 | 88797 | CVE-2016-1978 | BID:91787 | View |
| 772050 | 88797 | CVE-2016-1978 | URL:http://www.securityfocus.com/bid/91787 | View |
| 772051 | 88797 | CVE-2016-1978 | BID:84275 | View |
| 772052 | 88797 | CVE-2016-1978 | URL:http://www.securityfocus.com/bid/84275 | View |
| 772053 | 88797 | CVE-2016-1978 | SECTRACK:1035258 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 1173 | JVNDB-2016-001946 | 複数の Pro-face GP-Pro EX 製品における任意のコードを実行される脆弱性 | 複数の Pro-face GP-Pro EX 製品には、任意のコードを実行される、またはサービス運用妨害 (境界外読み取り) 状態にされる脆弱性が存在します。 | CVE-2016-2291 | 88797 | 4.3 | 6.5 | http://jvndb.jvn.jp/ja/contents/2016/JVNDB-2016-001946.html | View |