CVE-2018-12404: Mozilla Network Security Services

Medium severity, CVSS 5.9. EPSS: 44.2% chance of exploitation in the next 30 days.

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.

Affected products

  • Mozilla Network Security Services: before 3.41 (fixed in 3.41)

Published 2019-05-02. Last modified 2026-06-17.