CVE-2015-4490

Description

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.337

Associated Vulnerability

VulnerabilityOS Platform
Update for SeaMonkey (2.38)Windows
Update for Mozilla Firefox (40.0)Windows
Update for Mozilla Firefox (40.0.2)Windows
Update for Mozilla Firefox (40.0.3)Windows
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (40.0)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (40.0.2)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (40.0.3)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (140.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (140.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (140.0.2)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (140.0.4)Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 39.0.3Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-301495Update for SeaMonkey (2.38)
PATCH-302181Update for Mozilla Firefox (40.0)
PATCH-302182Update for Mozilla Firefox (40.0.2)
PATCH-302183Update for Mozilla Firefox (40.0.3)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234