Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23974
HistoryApr 10, 2020 - 12:42 a.m.

Erroneous Stylesheet Caching

2020-04-1000:42:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.013

Percentile

85.7%

SeaMonkey is vulnerable to erroneous stylesheet caching. The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser’s font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.