Oval Definition:oval:org.mitre.oval:def:24164
Revision Date:2014-10-06Version:18
Title:The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions
Description:The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2014-1485
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Mozilla SeaMonkey
Definition Synopsis
  • Related to Mozilla Firefox Mainline
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version less than 27.0
  • OR Related to Mozilla SeaMonkey
  • Mozilla Seamonkey is installed
  • AND Mozilla Seamonkey version less than 2.24
  • BACK