CVE-2013-5605

high
Published 2013-11-18 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-5605

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_notes

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — https://developer.mozilla.org/docs/NSS/NSS_3.14.5_release_notes

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2:3.15.3-1
debian debianbullseyefixed2:3.15.3-1
debian debianforkyfixed2:3.15.3-1
debian debiansidfixed2:3.15.3-1
debian debiantrixiefixed2:3.15.3-1

Application impact

VendorProductVersionsFixed
mozilla mozillanetwork_security_services3.14
mozilla mozillanetwork_security_services3.14.1
mozilla mozillanetwork_security_services3.14.2
mozilla mozillanetwork_security_services3.14.3
mozilla mozillanetwork_security_services3.14.4
mozilla mozillanetwork_security_services3.15
mozilla mozillanetwork_security_services3.15.1
mozilla mozillanetwork_security_services3.15.2

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.