CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-03-14T19:00:00

Updated: 2018-01-17T19:57:01

Reserved: 2012-01-09T00:00:00


Link: CVE-2012-0451

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-03-14T19:55:01.600

Modified: 2018-01-18T02:29:03.770


Link: CVE-2012-0451

JSON object: View

cve-icon Redhat Information

No data.

CWE