Heap-based Buffer Overflow in Mozilla NSS Leading to Potential Exploits
CVE-2017-11696
7.8HIGH
What is CVE-2017-11696?
A heap-based buffer overflow exists in the __hash_open function within Mozilla Network Security Services (NSS). This vulnerability allows context-dependent attackers to exploit the affected application by crafting a malicious cert8.db file, potentially leading to unauthorized actions. It is crucial for users and administrators to apply available updates to mitigate the risks associated with this vulnerability.