Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18635

Опубликовано: 25 сент. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

code not present
disco

not-affected

code not present
eoan

not-affected

code not present
esm-apps-legacy/xenial

released

1:0.4+dfsg+1+20131010+gitf68af8af3d-4+deb8u1build0.16.04.1
esm-apps/bionic

needed

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present

Показывать по

EPSS

Процентиль: 91%
0.0481
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
больше 7 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
nvd
почти 7 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

CVSS3: 6.1
debian
почти 7 лет назад

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the ...

CVSS3: 6.1
github
почти 6 лет назад

Cross-Site Scripting in @novnc/novnc

EPSS

Процентиль: 91%
0.0481
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3