LOW · 2.6

CVE-2014-1504

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct...

Vulnerability Description

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MozillaFirefox< 28.0
MozillaSeamonkey< 2.25
OpensuseOpensuse11.4
OracleSolaris11.3
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Sdk11
SuseLinux Enterprise Server11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1504?

CVE-2014-1504 is a vulnerability with a CVSS score of 2.6 (LOW). The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct...

How severe is CVE-2014-1504?

CVE-2014-1504 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1504?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Opensuse Opensuse, Oracle Solaris, Suse Linux Enterprise Desktop.