CVE-2014-1504

CWE-2646 documents6 sources
Severity
2.6LOW
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 13

Description

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages7 packages

NVDmozilla/firefox< 28.0
NVDmozilla/seamonkey< 2.25
NVDoracle/solaris11.3
NVDopensuse/opensuse11.4, 12.3, 13.1+2

🔴Vulnerability Details

2
GHSA
GHSA-5wjr-c7x3-p8gh: The session-restore feature in Mozilla Firefox before 282022-05-13
CVEList
CVE-2014-1504: The session-restore feature in Mozilla Firefox before 282014-03-19

📋Vendor Advisories

2
Red Hat
Mozilla: Content Security Policy for data: documents not preserved by session restore (MFSA 2014-23)2014-03-18
Ubuntu
Firefox vulnerabilities2014-03-18

💬Community

1
Bugzilla
CVE-2014-1504 Mozilla: Content Security Policy for data: documents not preserved by session restore (MFSA 2014-23)2014-03-17
CVE-2014-1504 (LOW CVSS 2.6) | The session-restore feature in Mozi | cvebase.io