Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
Conclusion & alert: CVE-2004-0826 is rated Moderate Risk (59.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.00%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 3.35% | 3.00% | -0.36% |
| 2 | 2025-03-29 | 3.00% | 3.35% | +0.36% |
| 3 | 2025-03-17 | — | 3.00% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mozilla | network_security_services | 3.2 | cpe:2.3:a:mozilla:network_security_services:3.2:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.2.1 | cpe:2.3:a:mozilla:network_security_services:3.2.1:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.3 | cpe:2.3:a:mozilla:network_security_services:3.3:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.3.1 | cpe:2.3:a:mozilla:network_security_services:3.3.1:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.3.2 | cpe:2.3:a:mozilla:network_security_services:3.3.2:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.4 | cpe:2.3:a:mozilla:network_security_services:3.4:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.4.1 | cpe:2.3:a:mozilla:network_security_services:3.4.1:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.4.2 | cpe:2.3:a:mozilla:network_security_services:3.4.2:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.5 | cpe:2.3:a:mozilla:network_security_services:3.5:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.6 | cpe:2.3:a:mozilla:network_security_services:3.6:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.6.1 | cpe:2.3:a:mozilla:network_security_services:3.6.1:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7 | cpe:2.3:a:mozilla:network_security_services:3.7:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7.1 | cpe:2.3:a:mozilla:network_security_services:3.7.1:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7.2 | cpe:2.3:a:mozilla:network_security_services:3.7.2:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7.3 | cpe:2.3:a:mozilla:network_security_services:3.7.3:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7.5 | cpe:2.3:a:mozilla:network_security_services:3.7.5:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.7.7 | cpe:2.3:a:mozilla:network_security_services:3.7.7:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.8 | cpe:2.3:a:mozilla:network_security_services:3.8:*:*:*:*:*:*:* |
| mozilla | network_security_services | 3.9 | cpe:2.3:a:mozilla:network_security_services:3.9:*:*:*:*:*:*:* |
| netscape | certificate_server | 1.0 | cpe:2.3:a:netscape:certificate_server:1.0:patch1:*:*:*:*:*:* |
| netscape | certificate_server | 4.2 | cpe:2.3:a:netscape:certificate_server:4.2:*:*:*:*:*:*:* |
| netscape | directory_server | 1.3 | cpe:2.3:a:netscape:directory_server:1.3:patch5:*:*:*:*:*:* |
| netscape | directory_server | 3.1 | cpe:2.3:a:netscape:directory_server:3.1:patch1:*:*:*:*:*:* |
| netscape | directory_server | 3.12 | cpe:2.3:a:netscape:directory_server:3.12:*:*:*:*:*:*:* |
| netscape | directory_server | 4.1 | cpe:2.3:a:netscape:directory_server:4.1:*:*:*:*:*:*:* |
| netscape | directory_server | 4.11 | cpe:2.3:a:netscape:directory_server:4.11:*:*:*:*:*:*:* |
| netscape | directory_server | 4.13 | cpe:2.3:a:netscape:directory_server:4.13:*:*:*:*:*:*:* |
| netscape | enterprise_server | 2.0 | cpe:2.3:a:netscape:enterprise_server:2.0:*:*:*:*:*:*:* |
| netscape | enterprise_server | 2.0.1c | cpe:2.3:a:netscape:enterprise_server:2.0.1c:*:*:*:*:*:*:* |
| netscape | enterprise_server | 2.0a | cpe:2.3:a:netscape:enterprise_server:2.0a:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.0 | cpe:2.3:a:netscape:enterprise_server:3.0:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.0.1 | cpe:2.3:a:netscape:enterprise_server:3.0.1:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.0.1b | cpe:2.3:a:netscape:enterprise_server:3.0.1b:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.0.7a | cpe:2.3:a:netscape:enterprise_server:3.0.7a:*:netware:*:*:*:*:* |
| netscape | enterprise_server | 3.0l | cpe:2.3:a:netscape:enterprise_server:3.0l:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.1 | cpe:2.3:a:netscape:enterprise_server:3.1:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.2 | cpe:2.3:a:netscape:enterprise_server:3.2:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.3 | cpe:2.3:a:netscape:enterprise_server:3.3:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.4 | cpe:2.3:a:netscape:enterprise_server:3.4:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.5 | cpe:2.3:a:netscape:enterprise_server:3.5:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.5 | cpe:2.3:a:netscape:enterprise_server:3.5:*:solaris:*:*:*:*:* |
| netscape | enterprise_server | 3.5.1 | cpe:2.3:a:netscape:enterprise_server:3.5.1:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.6 | cpe:2.3:a:netscape:enterprise_server:3.6:*:*:*:*:*:*:* |
| netscape | enterprise_server | 3.6 | cpe:2.3:a:netscape:enterprise_server:3.6:*:solaris:*:*:*:*:* |
| netscape | enterprise_server | 3.6 | cpe:2.3:a:netscape:enterprise_server:3.6:sp1:*:*:*:*:*:* |
| netscape | enterprise_server | 3.6 | cpe:2.3:a:netscape:enterprise_server:3.6:sp2:*:*:*:*:*:* |
| netscape | enterprise_server | 3.6 | cpe:2.3:a:netscape:enterprise_server:3.6:sp3:*:*:*:*:*:* |
| netscape | enterprise_server | 4.0 | cpe:2.3:a:netscape:enterprise_server:4.0:*:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp3:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp4:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp5:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp6:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp7:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1 | cpe:2.3:a:netscape:enterprise_server:4.1:sp8:*:*:*:*:*:* |
| netscape | enterprise_server | 4.1.1 | cpe:2.3:a:netscape:enterprise_server:4.1.1:*:netware:*:*:*:*:* |
| netscape | enterprise_server | 5.0 | cpe:2.3:a:netscape:enterprise_server:5.0:*:netware:*:*:*:*:* |
| netscape | personalization_engine | — | cpe:2.3:a:netscape:personalization_engine:*:*:*:*:*:*:*:* |
| sun | java_enterprise_system | 2003q4 | cpe:2.3:a:sun:java_enterprise_system:2003q4:*:*:*:*:*:*:* |
| sun | java_enterprise_system | 2004q2 | cpe:2.3:a:sun:java_enterprise_system:2004q2:*:*:*:*:*:*:* |
| sun | java_system_application_server | 7.0 | cpe:2.3:a:sun:java_system_application_server:7.0:*:enterprise:*:*:*:*:* |
| sun | java_system_application_server | 7.0 | cpe:2.3:a:sun:java_system_application_server:7.0:*:platform:*:*:*:*:* |
| sun | java_system_application_server | 7.0 | cpe:2.3:a:sun:java_system_application_server:7.0:*:standard:*:*:*:*:* |
| sun | java_system_application_server | 7.0 | cpe:2.3:a:sun:java_system_application_server:7.0:ur4:*:*:*:*:*:* |
| sun | java_system_application_server | 7.1 | cpe:2.3:a:sun:java_system_application_server:7.1:*:*:*:*:*:*:* |
| sun | one_application_server | 6.0 | cpe:2.3:a:sun:one_application_server:6.0:*:*:*:*:*:*:* |
| sun | one_application_server | 6.0 | cpe:2.3:a:sun:one_application_server:6.0:sp1:*:*:*:*:*:* |
| sun | one_application_server | 6.0 | cpe:2.3:a:sun:one_application_server:6.0:sp2:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:*:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp1:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp10:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp11:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp12:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp13:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp14:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp2:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp3:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp4:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp5:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp6:*:*:*:*:*:* |
| sun | one_web_server | 4.1 | cpe:2.3:a:sun:one_web_server:4.1:sp7:*:*:*:*:*:* |