CVE-2014-1485
06.02.2014, 05:44
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 27.0 |
mozilla | seamonkey | 𝑥 < 2.24 |
oracle | solaris | 11.3 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
canonical | ubuntu_linux | 13.10 |
opensuse | opensuse | 11.4 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References