CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects Firefox. It may be remotely exploitable.
CVE
CVE-2014-1485
Severity
HIGH
CVSS
7.5
EPSS
3.00%
Firefox
Original NVD Description
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.