CVE-2017-11697: Mozilla Network Security Services

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.

Affected products

  • Mozilla Network Security Services: affected versions not specified

Published 2017-12-27. Last modified 2026-06-17.