Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-4510 | The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior. |
Ubuntu USN |
USN-2702-1 | Firefox vulnerabilities |
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T06:18:11.636Z
Reserved: 2015-06-10T00:00:00.000Z
Link: CVE-2015-4490
No data.
Status : Modified
Published: 2015-08-16T01:59:18.080
Modified: 2026-06-17T00:27:23.390
Link: CVE-2015-4490
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Ubuntu USN