4.3
CVSSv2

CVE-2014-1591

Published: 11/12/2014 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox 33.0 and SeaMonkey prior to 2.31 include path strings in CSP violation reports, which allows remote malicious users to obtain sensitive information via a web site that receives a report after a redirect.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey

mozilla firefox 33.0

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-86 CSP leaks redirect data via violation reports Announced December 2, 2014 Reporter Muneaki Nishimura Impact High Products Firefox, Firefox OS, SeaMonkey Fixed in ...