A vulnerability, known as BigSig, was discovered in Mozilla's Network Security Services (NSS) cryptography library, which is widely used. The bug is a simple buffer overflow that can cause memory corruption, and it was found using a combination of stack coverage and object isolation fuzzing techniques. The vulnerability was not caught by existing fuzzing and testing efforts, despite Mozilla's mature security team and extensive testing infrastructure. The bug has been resolved in NSS 3.73.0.