CVE-2017-11696: Mozilla Network Security Services
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Affected products
- Mozilla Network Security Services: affected versions not specified
Published 2017-12-27. Last modified 2026-06-17.