CVE detail
CVE-2016-5285 — CVE-2016-5285
Published 2019-11-15 · Modified 2026-06-17 · Vendor mozilla · Product nss · Source nvd
HIGH
severity
CVSS-derived band
0.0228
EPSS probability
exploitation probability, 30d
82.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References