// For flags

CVE-2006-3127

 

Severity Score

7.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.

Fallo de memoria en la Red de Servicios de Seguridad (NSS) 3.11, tal como se utiliza en Sun Java Enterprise System 2003Q4 2005Q1 y por medio de Java System Directory Server 5.2, permite a atacantes remotos causar una denegación de servicio (consumo de memoria) mediante la realización de un gran número de operaciones de cifrado RSA .

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-06-21 CVE Reserved
  • 2006-06-21 CVE Published
  • 2023-11-14 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sun
Search vendor "Sun"
Java Enterprise System
Search vendor "Sun" for product "Java Enterprise System"
2003q4
Search vendor "Sun" for product "Java Enterprise System" and version "2003q4"
-
Affected
Sun
Search vendor "Sun"
Java Enterprise System
Search vendor "Sun" for product "Java Enterprise System"
2004q2
Search vendor "Sun" for product "Java Enterprise System" and version "2004q2"
-
Affected
Sun
Search vendor "Sun"
Java Enterprise System
Search vendor "Sun" for product "Java Enterprise System"
2005q1
Search vendor "Sun" for product "Java Enterprise System" and version "2005q1"
-
Affected
Sun
Search vendor "Sun"
Java System Directory Server
Search vendor "Sun" for product "Java System Directory Server"
5.2
Search vendor "Sun" for product "Java System Directory Server" and version "5.2"
-
Affected