Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 24 results


CVE-2020-11023

Low priority
Vulnerable

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....

2 affected packages

drupal7, jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
drupal7 Not in release Not in release Not in release Not in release Needs evaluation
jquery Not in release Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2018-18405

Medium priority
Ignored

** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.

1 affected packages

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jquery Not affected Not affected Not affected
Show less packages

CVE-2019-11358

Low priority
Vulnerable

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...

5 affected packages

drupal7, jquery, mediawiki, node-jquery, otrs2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
drupal7 Not in release Not in release Not in release Not in release Needs evaluation
jquery Not in release Not in release Not affected Vulnerable Vulnerable
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
node-jquery Not affected Not affected Not affected Vulnerable Vulnerable
otrs2 Not in release Needs evaluation Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2018-9206

High priority
Fixed

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

1 affected packages

libjs-jquery-file-upload

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libjs-jquery-file-upload Fixed Not in release
Show less packages

CVE-2016-10707

Medium priority
Not affected

jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding...

1 affected packages

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jquery Not affected
Show less packages

CVE-2015-9251

Low priority
Ignored

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

1 affected packages

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jquery Not affected Not affected Ignored
Show less packages

CVE-2012-6708

Low priority
Vulnerable

jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input...

1 affected packages

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jquery Not in release Not in release Not affected Not affected Not affected
Show less packages

CVE-2014-6071

Low priority
Ignored

jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.

1 affected packages

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jquery
Show less packages

CVE-2016-7103

Medium priority

Some fixes available 2 of 6

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

1 affected packages

jqueryui

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
jqueryui Not affected Not affected Not affected Fixed
Show less packages

CVE-2015-1840

Medium priority
Ignored

jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of...

1 affected packages

ruby-jquery-rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-jquery-rails Not affected Not affected
Show less packages