Home CVE Database CVE-2015-7181



The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a use-after-poison issue.

Priority: High
CVSS v3: 0.0
Publish Date: Nov 5, 2015
Related ID: --
CVSS v2: 7.5
Modified Date: Nov 5, 2015

Find out more about CVE-2015-7181 from the MITRE-CVE dictionary and NIST NVD

Products Affected

Login may be required to access defects or downloads.

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --



Live chat