{"id":"CVE-2018-18508","details":"In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.","modified":"2026-03-12T22:48:20.100960Z","published":"2020-10-22T21:15:12.467Z","related":["SUSE-SU-2019:3395-1","openSUSE-SU-2020:0008-1"],"references":[{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf"},{"type":"ADVISORY","url":"https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.7_release_notes"},{"type":"ADVISORY","url":"https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.41.1_release_notes"},{"type":"ADVISORY","url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"3.36.7"}]},{"events":[{"introduced":"3.41"},{"fixed":"3.41.1"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.14.0"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-18508.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}