Show filters
49 Total Results
Displaying 41-49 of 49
Sort by:
Attacker Value
Unknown

CVE-2016-10707

Disclosure Date: January 18, 2018 (last updated February 10, 2024)
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.
Attacker Value
Unknown

CVE-2014-6071

Disclosure Date: January 16, 2018 (last updated November 26, 2024)
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.
0
Attacker Value
Unknown

CVE-2017-1000170

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
jqueryFileTree 2.1.5 and older Directory Traversal
Attacker Value
Unknown

CVE-2015-7943

Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
0
Attacker Value
Unknown

CVE-2015-2089

Disclosure Date: February 26, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (XSS) attacks via the (2) csj_width, (3) csj_height, (4) csj_sleep, (5) csj_fade, or (6) upload_image parameter in the thisismyurl_csj.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2012-6662

Disclosure Date: November 24, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
0
Attacker Value
Unknown

CVE-2010-5312

Disclosure Date: November 24, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
Attacker Value
Unknown

CVE-2011-4969

Disclosure Date: March 08, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
0
Attacker Value
Unknown

CVE-2007-2379

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."
0