CVE-2017-5461: Mozilla Network Security Services

Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

Affected products

  • Mozilla Network Security Services: before 3.21.4 (fixed in 3.21.4); after 3.22, before 3.28.4 (fixed in 3.28.4); from 3.29, before 3.29.5 (fixed in 3.29.5); from 3.30, before 3.30.1 (fixed in 3.30.1)

Published 2017-05-11. Last modified 2026-06-17.