Total vulnerabilities in the database
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
Software | From | Fixed in |
---|---|---|
mozilla / seamonkey | - | 2.24 |
mozilla / firefox | - | 27.0 |
oracle / solaris | 11.3 | 11.3.x |
canonical / ubuntu_linux | 13.10 | 13.10.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
suse / linux_enterprise_desktop | 11-sp3 | 11-sp3.x |
suse / linux_enterprise_server | 11-sp3 | 11-sp3.x |
opensuse / opensuse | 12.3 | 12.3.x |
suse / linux_enterprise_software_development_kit | 11-sp3 | 11-sp3.x |
opensuse / opensuse | 11.4 | 11.4.x |
opensuse / opensuse | 13.1 | 13.1.x |