CVE-2017-11698: Mozilla Network Security Services

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

Affected products

  • Mozilla Network Security Services: affected versions not specified

Published 2017-12-27. Last modified 2026-06-17.