CVE-2014-1492

Exp

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Published: 2014-03-25 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-1492 is rated Exploit Available (59.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.77%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2014-1492

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2014-1492

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.83% 1.77% +0.94%
2 2026-03-27 1.19% 0.83% -0.36%
3 2026-02-22 1.19%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-1492

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2014-1492

OS Trackers for CVE-2014-1492

vendor priority summary link
debian not yet assigned CVE-2014-1492 not yet assigned priority: Debian including 1 source packages (nss), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-1492
gentoo normal CVE-2014-1492: 1 GLSA(s) (201504-01), 7 atom(s) (dev-libs/nspr, mail-client/thunderbird, …); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-1492
redhat low https://access.redhat.com/security/cve/CVE-2014-1492
suse medium CVE-2014-1492 severity moderate: SUSE including 237 source package names (MozillaFirefox, MozillaFirefox-140.2.0-160000.1.2, …), 649 product×package rows across 69 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 7.1, … (69 product lines)): Known Not Affected 349, Fixed 300. https://www.suse.com/security/cve/CVE-2014-1492/
ubuntu medium CVE-2014-1492 medium priority: Ubuntu including 5 source packages (chromium-browser, firefox, nss, oxide-qt, thunderbird), 30 status rows across 6 suites (lucid, precise, quantal, saucy, trusty, upstream): released 11, DNE 7, not-affected 5, ignored 4, needs-triage 3. https://ubuntu.com/security/CVE-2014-1492

Affected software / configurations for CVE-2014-1492

Vendor Product Version Raw CPE
mozilla network_security_services <= 3.15.5 cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*
mozilla network_security_services 3.2 cpe:2.3:a:mozilla:network_security_services:3.2:*:*:*:*:*:*:*
mozilla network_security_services 3.2.1 cpe:2.3:a:mozilla:network_security_services:3.2.1:*:*:*:*:*:*:*
mozilla network_security_services 3.3 cpe:2.3:a:mozilla:network_security_services:3.3:*:*:*:*:*:*:*
mozilla network_security_services 3.3.1 cpe:2.3:a:mozilla:network_security_services:3.3.1:*:*:*:*:*:*:*
mozilla network_security_services 3.3.2 cpe:2.3:a:mozilla:network_security_services:3.3.2:*:*:*:*:*:*:*
mozilla network_security_services 3.4 cpe:2.3:a:mozilla:network_security_services:3.4:*:*:*:*:*:*:*
mozilla network_security_services 3.4.1 cpe:2.3:a:mozilla:network_security_services:3.4.1:*:*:*:*:*:*:*
mozilla network_security_services 3.4.2 cpe:2.3:a:mozilla:network_security_services:3.4.2:*:*:*:*:*:*:*
mozilla network_security_services 3.5 cpe:2.3:a:mozilla:network_security_services:3.5:*:*:*:*:*:*:*
mozilla network_security_services 3.6 cpe:2.3:a:mozilla:network_security_services:3.6:*:*:*:*:*:*:*
mozilla network_security_services 3.6.1 cpe:2.3:a:mozilla:network_security_services:3.6.1:*:*:*:*:*:*:*
mozilla network_security_services 3.7 cpe:2.3:a:mozilla:network_security_services:3.7:*:*:*:*:*:*:*
mozilla network_security_services 3.7.1 cpe:2.3:a:mozilla:network_security_services:3.7.1:*:*:*:*:*:*:*
mozilla network_security_services 3.7.2 cpe:2.3:a:mozilla:network_security_services:3.7.2:*:*:*:*:*:*:*
mozilla network_security_services 3.7.3 cpe:2.3:a:mozilla:network_security_services:3.7.3:*:*:*:*:*:*:*
mozilla network_security_services 3.7.5 cpe:2.3:a:mozilla:network_security_services:3.7.5:*:*:*:*:*:*:*
mozilla network_security_services 3.7.7 cpe:2.3:a:mozilla:network_security_services:3.7.7:*:*:*:*:*:*:*
mozilla network_security_services 3.8 cpe:2.3:a:mozilla:network_security_services:3.8:*:*:*:*:*:*:*
mozilla network_security_services 3.9 cpe:2.3:a:mozilla:network_security_services:3.9:*:*:*:*:*:*:*
mozilla network_security_services 3.11.2 cpe:2.3:a:mozilla:network_security_services:3.11.2:*:*:*:*:*:*:*
mozilla network_security_services 3.11.3 cpe:2.3:a:mozilla:network_security_services:3.11.3:*:*:*:*:*:*:*
mozilla network_security_services 3.11.4 cpe:2.3:a:mozilla:network_security_services:3.11.4:*:*:*:*:*:*:*
mozilla network_security_services 3.11.5 cpe:2.3:a:mozilla:network_security_services:3.11.5:*:*:*:*:*:*:*
mozilla network_security_services 3.12 cpe:2.3:a:mozilla:network_security_services:3.12:*:*:*:*:*:*:*
mozilla network_security_services 3.12.1 cpe:2.3:a:mozilla:network_security_services:3.12.1:*:*:*:*:*:*:*
mozilla network_security_services 3.12.2 cpe:2.3:a:mozilla:network_security_services:3.12.2:*:*:*:*:*:*:*
mozilla network_security_services 3.12.3 cpe:2.3:a:mozilla:network_security_services:3.12.3:*:*:*:*:*:*:*
mozilla network_security_services 3.12.3.1 cpe:2.3:a:mozilla:network_security_services:3.12.3.1:*:*:*:*:*:*:*
mozilla network_security_services 3.12.3.2 cpe:2.3:a:mozilla:network_security_services:3.12.3.2:*:*:*:*:*:*:*
mozilla network_security_services 3.12.4 cpe:2.3:a:mozilla:network_security_services:3.12.4:*:*:*:*:*:*:*
mozilla network_security_services 3.12.5 cpe:2.3:a:mozilla:network_security_services:3.12.5:*:*:*:*:*:*:*
mozilla network_security_services 3.12.6 cpe:2.3:a:mozilla:network_security_services:3.12.6:*:*:*:*:*:*:*
mozilla network_security_services 3.12.7 cpe:2.3:a:mozilla:network_security_services:3.12.7:*:*:*:*:*:*:*
mozilla network_security_services 3.12.8 cpe:2.3:a:mozilla:network_security_services:3.12.8:*:*:*:*:*:*:*
mozilla network_security_services 3.12.9 cpe:2.3:a:mozilla:network_security_services:3.12.9:*:*:*:*:*:*:*
mozilla network_security_services 3.12.10 cpe:2.3:a:mozilla:network_security_services:3.12.10:*:*:*:*:*:*:*
mozilla network_security_services 3.12.11 cpe:2.3:a:mozilla:network_security_services:3.12.11:*:*:*:*:*:*:*
mozilla network_security_services 3.14 cpe:2.3:a:mozilla:network_security_services:3.14:*:*:*:*:*:*:*
mozilla network_security_services 3.14.1 cpe:2.3:a:mozilla:network_security_services:3.14.1:*:*:*:*:*:*:*
mozilla network_security_services 3.14.2 cpe:2.3:a:mozilla:network_security_services:3.14.2:*:*:*:*:*:*:*
mozilla network_security_services 3.14.3 cpe:2.3:a:mozilla:network_security_services:3.14.3:*:*:*:*:*:*:*
mozilla network_security_services 3.14.4 cpe:2.3:a:mozilla:network_security_services:3.14.4:*:*:*:*:*:*:*
mozilla network_security_services 3.14.5 cpe:2.3:a:mozilla:network_security_services:3.14.5:*:*:*:*:*:*:*
mozilla network_security_services 3.15 cpe:2.3:a:mozilla:network_security_services:3.15:*:*:*:*:*:*:*
mozilla network_security_services 3.15.1 cpe:2.3:a:mozilla:network_security_services:3.15.1:*:*:*:*:*:*:*
mozilla network_security_services 3.15.2 cpe:2.3:a:mozilla:network_security_services:3.15.2:*:*:*:*:*:*:*
mozilla network_security_services 3.15.3 cpe:2.3:a:mozilla:network_security_services:3.15.3:*:*:*:*:*:*:*
mozilla network_security_services 3.15.3.1 cpe:2.3:a:mozilla:network_security_services:3.15.3.1:*:*:*:*:*:*:*
mozilla network_security_services 3.15.4 cpe:2.3:a:mozilla:network_security_services:3.15.4:*:*:*:*:*:*:*

References for CVE-2014-1492

URL Tags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.html
http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00015.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00010.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00033.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://secunia.com/advisories/59866
http://secunia.com/advisories/60621
http://secunia.com/advisories/60794
http://www.debian.org/security/2014/dsa-2994
http://www.mozilla.org/security/announce/2014/mfsa2014-45.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.securityfocus.com/bid/66356
http://www.ubuntu.com/usn/USN-2159-1
http://www.ubuntu.com/usn/USN-2185-1
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
https://bugzilla.mozilla.org/show_bug.cgi?id=903885
https://bugzilla.redhat.com/show_bug.cgi?id=1079851
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.16_release_notes
https://hg.mozilla.org/projects/nss/rev/709d4e597979 Exploit Patch
https://security.gentoo.org/glsa/201504-01
cvelogic Threat Intelligence