Revision Date: | 2014-10-06 | Version: | 18 |
Title: | The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions |
Description: | The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions. |
Family: | windows | Class: | vulnerability |
Status: | ACCEPTED | Reference(s): | CVE-2014-1485
|
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows XP
| Product(s): | Mozilla Firefox Mozilla SeaMonkey
|
Definition Synopsis |
Related to Mozilla Firefox Mainline Mozilla Firefox Mainline release is installed
AND Mozilla Firefox Mainline version less than 27.0
OR Related to Mozilla SeaMonkey
Mozilla Seamonkey is installed
AND Mozilla Seamonkey version less than 2.24
|