CVE-2014-1504
Severity
2.6LOW
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 19
Latest updateMay 13
Description
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.
CVSS vector
AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9
Affected Packages7 packages
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2014-1504 Mozilla: Content Security Policy for data: documents not preserved by session restore (MFSA 2014-23)↗2014-03-17