← Vulnerability feed

Vulnerability record · CVE-2016-5285 · published 15 November 2019

CVE-2016-5285: Mozilla nss null pointer dereference vulnerability

Mozilla · Nss

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

7.5 CVSS 3.1 High EPSS 2.3% · top 17.5% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
27Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

27 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5285 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-5096Avaya aura application server 5300 memory buffer overflow vulnerabilityStack-based buffer overflow in cstore.exe in the Media Application Server (MAS) in Avaya Aura Application Server 5300 (formerly Nortel Media Applicat…EPSS 3.9%8.8CVE-2020-7029Avaya aura communication manager cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager…EPSS 0.43%8.6CVE-2019-7007Avaya aura conferencing path traversal vulnerabilityA directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could…EPSS 1.7%8.1CVE-2010-2943Linux kernel information exposure vulnerabilityThe xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote a…EPSS 17%7.8CVE-2010-2492Linux kernel classic buffer overflow vulnerabilityBuffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow loc…EPSS 0.43%7.8CVE-2010-2798Linux kernel null pointer dereference vulnerabilityThe gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with s…EPSS 0.41%7.5CVE-2018-15617Avaya aura communication manager vulnerabilityA vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to c…EPSS 2.2%7.1CVE-2009-3939Linux kernel incorrect permission assignment vulnerabilityThe poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2016-5285), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.