Search CVE reports


Toggle filters

11 – 20 of 29 results


CVE-2020-28488

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

jqueryui

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jqueryui Not affected Not affected
Show less packages

CVE-2020-23064

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11023. Reason: This candidate is a duplicate of CVE-2020-11023. Notes: All CVE users should reference CVE-2020-11023 instead of this candidate. All references...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not in release Not in release Not affected Not affected
Show less packages

CVE-2020-11023

High priority

Some fixes available 4 of 5

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....

2 affected packages

jquery, drupal7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not in release Not in release Fixed Fixed
drupal7 Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-11022

Low priority

Some fixes available 5 of 6

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may...

2 affected packages

drupal7, jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
drupal7 Not in release Not in release Not in release Not in release
jquery Not in release Not in release Fixed Fixed
Show less packages

CVE-2019-5428

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of CVE-2019-11358. Notes: All CVE users should reference CVE-2019-11358 instead of this candidate. All references...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Ignored
Show less packages

CVE-2019-11358

Low priority

Some fixes available 3 of 29

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...

5 affected packages

drupal7, jquery, node-jquery, mediawiki, otrs2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
drupal7 Not in release Not in release Not in release Not in release
jquery Not in release Not in release Not affected Fixed
node-jquery Not affected Not affected Not affected Vulnerable
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
otrs2 Not in release Needs evaluation Not affected Needs evaluation
Show less packages

CVE-2018-9206

High priority
Fixed

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

1 affected package

libjs-jquery-file-upload

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjs-jquery-file-upload Fixed
Show less packages

CVE-2018-18405

Medium priority
Ignored

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not affected Not affected
Show less packages

CVE-2017-16011

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of CVE-2012-6708. Notes: All CVE users should reference CVE-2012-6708 instead of this candidate. All references...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not affected
Show less packages

CVE-2016-7103

Medium priority

Some fixes available 2 of 6

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

1 affected package

jqueryui

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jqueryui Not affected Not affected Not affected
Show less packages