Логотип exploitDog
bind:CVE-2015-4490
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-4490

Количество 6

Количество 6

ubuntu логотип

CVE-2015-4490

больше 10 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-4490

больше 10 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2015-4490

больше 10 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-4490

больше 10 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in M ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-346h-r83r-9vqj

больше 3 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

EPSS: Низкий
fstec логотип

BDU:2015-11246

больше 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю проводить межсайтовый скриптинг

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-4490

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-4490

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 5.1
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-4490

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-4490

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in M ...

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
github логотип
GHSA-346h-r83r-9vqj

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2015-11246

Уязвимость браузера Firefox, позволяющая нарушителю проводить межсайтовый скриптинг

CVSS2: 4.3
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу