Appsecure logo

CVE-2021-43527: Critical Vulnerability in Mozilla NSS

A critical heap overflow vulnerability in NSS (Network Security Services) can lead to severe impacts on applications using this library. Organizations should prioritize immediate patching to prevent exploitation.

CRITICALCVSS 9.8 · Published December 8, 2021

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. This vulnerability allows applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 to be impacted. Moreover, applications relying on NSS for certificate validation or other TLS, X.509, OCSP, or CRL functionality may also be at risk, depending on their configuration of NSS.

It is important to note that this vulnerability does NOT impact Mozilla Firefox. However, email clients and PDF viewers that utilize NSS for signature verification, such as Thunderbird, LibreOffice, Evolution, and Evince, are believed to be affected. The urgency for organizations to address this vulnerability cannot be overstated, as it presents a critical risk.

The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Risk to organizations includes potential unauthorized access and data corruption, making it imperative for organizations to prioritize patching immediately.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.