CVE-2014-1591 PUBLISHED

Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.

EPSS 0.27% · 50.5th percentile

Risk Scores

EPSS Score
0.27%
50.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSfirefox0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1

Timeline

References

Open in Interactive Console →