Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

jQuery

jQueryнабор функций JavaScript, фокусирующийся на взаимодействии JavaScript и HTML.

Релизный цикл, информация об уязвимостях

Продукт: jQuery
Вендор: jquery

График релизов

12342006200720082009201020112012201320142015201620172018201920202021202220232024202520262027

Недавние уязвимости jQuery

Количество 85

nvd логотип

CVE-2020-11023

больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
EPSS: Высокий
debian логотип

CVE-2020-11023

больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, pa ...

CVSS3: 6.9
EPSS: Высокий
ubuntu логотип

CVE-2020-11023

больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
EPSS: Высокий
redhat логотип

CVE-2020-11023

больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
EPSS: Высокий
fstec логотип

BDU:2020-05190

больше 6 лет назад

Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.1
EPSS: Критический
fstec логотип

BDU:2020-04949

больше 6 лет назад

Уязвимость библиотеки jQuery, существующая из-за недостаточной очистки предоставленных пользователем данных при передаче элементов <option>, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
EPSS: Высокий
redhat логотип

CVE-2020-11022

больше 6 лет назад

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
EPSS: Критический
nvd логотип

CVE-2018-18405

больше 6 лет назад

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-18405

больше 6 лет назад

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG ele ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-18405

больше 6 лет назад

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
84%
Высокий
больше 6 лет назад
debian логотип
CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, pa ...

CVSS3: 6.9
84%
Высокий
больше 6 лет назад
ubuntu логотип
CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
84%
Высокий
больше 6 лет назад
redhat логотип
CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
84%
Высокий
больше 6 лет назад
fstec логотип
BDU:2020-05190

Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.1
99%
Критический
больше 6 лет назад
fstec логотип
BDU:2020-04949

Уязвимость библиотеки jQuery, существующая из-за недостаточной очистки предоставленных пользователем данных при передаче элементов <option>, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
84%
Высокий
больше 6 лет назад
redhat логотип
CVE-2020-11022

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
99%
Критический
больше 6 лет назад
nvd логотип
CVE-2018-18405

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-18405

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG ele ...

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-18405

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

CVSS3: 6.1
2%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться