VulnerabilityModified
CVE-2010-5312
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
MEDIUM 6.1EPSS 18.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 18.35% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- debian/debian linux · jqueryui/jquery ui · fedoraproject/fedora · netapp/snapcenter · apache/drill · drupal/drupal
- Source
- cve@mitre.org
References
- http://bugs.jqueryui.com/ticket/6016Exploit, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0442.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1462.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/613Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q4/616Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3249Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/71106Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037035Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98696Third Party Advisory, VDB Entry
- https://github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3Vendor Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190416-0007/Third Party Advisory
- https://www.drupal.org/sa-core-2022-002Third Party Advisory
- http://bugs.jqueryui.com/ticket/6016Exploit, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0442.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1462.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/613Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q4/616Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3249Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/71106Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037035Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98696Third Party Advisory, VDB Entry
- https://github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.