The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2015-11-05T02:00:00

Updated: 2016-12-05T22:57:01

Reserved: 2015-06-10T00:00:00


Link: CVE-2015-4518

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-11-05T05:59:04.570

Modified: 2016-12-07T18:13:15.430


Link: CVE-2015-4518

JSON object: View

cve-icon Redhat Information

No data.

CWE