Summary
This host is installed with Mozilla Firefox
and is prone to information disclosure vulnerability.
Impact
Successful exploitation will allow remote
attackers to gain access to usernames or single-sign-on tokens.
Impact Level: Application
Solution
Upgrade to Mozilla Firefox version 34.0
or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Insight
Flaw exists due to an error when handling
Content Security Policy (CSP) violation reports triggered by a redirect.
Affected
Mozilla Firefox version 33.0 on Mac OS X
Detection
Get the installed version with the help of
detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-1591 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities (Win)
- Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
- Apple Mac OS X Authentication Bypass Vulnerability
- Adobe Reader Privelege Escalation Vulnerability - Jul07 (Mac OS X)
- Apache Tomcat servlet/JSP container default files