Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
Moderate
CVE-2015-9251
Disclosure Date: January 18, 2018 (last updated November 08, 2023)
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
6
Attacker Value
Unknown
CVE-2020-11022
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
4
Attacker Value
Unknown
CVE-2016-9677
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9678
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9680
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9676
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9679
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
0