Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 安全漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 40.0之前版本的dom/security/nsCSPUtils.cpp文件中的‘nsCSPHostSrc::permits’函数存在安全漏洞,该漏洞源于程序匹配通配符source-expression时没有正确处理blob:、data:和filesystem: URL的Content Security Policy Level 2异常。远程攻击者可借助policy-enforcement
CVSS Information
N/A
Vulnerability Type
N/A