CVE-2015-2730: Debian Linux
Medium severity, CVSS 4.3. EPSS: 3.6% chance of exploitation in the next 30 days.
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Mozilla Network Security Services: up to and including 3.19
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Server: version 11 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Oracle Solaris: version 11.3 only
- Oracle Vm Server: version 3.2 only
Published 2015-07-06. Last modified 2026-06-17.