2.6
CVSSv2

CVE-2014-1504

Published: 19/03/2014 Updated: 10/08/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The session-restore feature in Mozilla Firefox prior to 28.0 and SeaMonkey prior to 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla seamonkey

opensuse opensuse 11.4

opensuse opensuse 12.3

opensuse opensuse 13.1

oracle solaris 11.3

suse linux enterprise desktop 11

suse linux enterprise sdk 11

suse linux enterprise server 11

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-23 Content Security Policy for data: documents not preserved by session restore Announced March 18, 2014 Reporter Nicolas Golubovic Impact Low Products Firefox, SeaMonkey Fixed ...