Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1485

Опубликовано: 06 фев. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

РелизСтатусПримечание
devel

not-affected

lucid

ignored

end of life
precise

released

27.0+build1-0ubuntu0.12.04.1
quantal

released

27.0+build1-0ubuntu0.12.10.1
saucy

released

27.0+build1-0ubuntu0.13.10.1
upstream

released

27.0

Показывать по

EPSS

Процентиль: 76%
0.00964
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

nvd
больше 11 лет назад

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

debian
больше 11 лет назад

The Content Security Policy (CSP) implementation in Mozilla Firefox be ...

github
больше 3 лет назад

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

fstec
больше 11 лет назад

Уязвимость в программном продукте Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код

EPSS

Процентиль: 76%
0.00964
Низкий

7.5 High

CVSS2