CVE-2014-1591 describes an information disclosure vulnerability in Mozilla Firefox 33.0 and SeaMonkey before 2.31. These browsers inadvertently included path strings in Content Security Policy (CSP) violation reports, allowing remote attackers to obtain sensitive information if a website received such a report after a redirect. The vulnerability has a CVSS score of 4.3 (medium severity), indicating a network-based attack with medium complexity and potential for partial confidentiality impact. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, though it did receive some community and media attention at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
33.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:33.0:*:*:*:*:*:*:* | ||
<= 2.30CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.