CVE-2017-7502: Mozilla Network Security Services
High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Affected products
- Mozilla Network Security Services: version 3.24.0 only; version 3.25.0 only; version 3.25.1 only; version 3.26.0 only; version 3.26.2 only; version 3.27.0 only; …
Published 2017-05-30. Last modified 2026-06-17.