CVE-2011-5094: Mozilla Network Security Services
Medium severity, CVSS 4.3. EPSS: 2.7% chance of exploitation in the next 30 days.
Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment
Affected products
- Mozilla Network Security Services: version 3.2 only; version 3.2.1 only; version 3.3 only; version 3.3.1 only; version 3.3.2 only; version 3.4 only; …
Published 2012-06-16. Last modified 2026-06-16.