Vulnerabilities in Open Source Libraries Salesforce
-
Vulnerabilities in Open Source Libraries List
-
AngularJS – Denial of Service attack through DOM clobbering on versions under 1.6.3
-
AngularJS – Prototype Pollution Vulnerability Under 1.7.9
-
AngularJS – XSS vulnerability Using AngularJS Under 1.6.5 In Firefox And Safari – Sanitize On Inert Documents
-
AngularJS – XSS Vulnerability Through The Attribute “usemap” From 1.0.0 To 1.2.30
-
AngularJS – XSS Vulnerability Through The Attribute “usemap” From 1.3.0 To 1.5.0-rc2
-
AngularJS – XSS Vulnerability Under 1.8.0 – Input HTML
-
AngularJS – XSS Vulnerability Using AngularJS Under 1.6.9 With Firefox
-
jQuery – XSS Vulnerability Under 3.5.0, When Using htmlPrefilter
-
XSS Vulnerability In Ext JS Action Column getTip
-
jQuery – Prototype Pollution Vulnerability Under 3.4.0
-
jQuery – XSS Vulnerability Under 1.6.3, When Using location.hash
-
jQuery – XSS Vulnerability Under 1.9.0, When Using jQuery(strInput)
-
jQuery – XSS Vulnerability Under 3.0.0, When Making Cross-Domain Calls Without The dataType Option
-
jQuery-ui-tooltip – XSS Vulnerability Under 1.10.0, Title Attribute
-
jQuery-ui-dialog – XSS Vulnerability Under 1.10.0, Title Attribute
-
jQuery-ui-dialog – XSS Vulnerability Under 1.10.0, closeText Parameter
-
moment.js – Regular Expression Denial Of Service Vulnerability
-
Bootstrap – XSS Vulnerability On Versions Under 2.1.0, On popover / tooltip
-
Bootstrap – XSS Vulnerability On Versions Under 3.4.0, On data-target Attribute
-
Bootstrap – XSS Vulnerability On Versions Between 4.0.0 And 4.1.2, On data-target Attribute
-
Bootstrap – XSS Vulnerability On Versions Under 3.4.1, On data-template, data-content And data-Title Attributes
-
Bootstrap – XSS Vulnerability On Versions Between 4.0.0 And 4.3.1, On data-template, data-content And data-title Attributes
-
swfobject – XSS Vulnerability On Versions Under 2.1, On swfobject.getQueryParamValue
-
tinyMCE – Static Code Injection Vulnerability On Versions Under 1.4.2, In inc/function.base.php
-
tinyMCE – XSS Vulnerability On Versions Under 4.2.4, In Media Plugin
-
tinyMCE – XSS Vulnerability On Versions Under 4.2.0, In Some Default Config Implementations
-
tinyMCE – XSS Vulnerability On Versions Under 4.7.12, In Links With XLINK:HREF Attributes
-
tinyMCE – XSS Vulnerability On Versions Under 5.1.6, In CDATA Elements
-
tinyMCE – XSS Vulnerability On Versions Under 5.2.2, In Media Elements
-
tinyMCE – XSS Vulnerability On Versions Under 5.4.0, In iframe Elements
-
tinyMCE – XSS Vulnerability On Versions Between 5.0.0 And 5.1.4, On The Core Parser, Paste And visualcharts Plugins
-
AngularJS – XSS Vulnerability On Versions Under 1.8.0, Via JQLite DOM Manipulation Functions
-
AngularJS – XSS Vulnerability On Versions Under 1.8.0, Via Nested Option In Select Elements
-
jQuery – XSS Vulnerability On Versions Under 3.5.0, Via The htmlPrefilter Method
-
Handlebars – Remote Code Execution Possible In Compat And Strict Mode On Versions Under 4.7.7
-
Handlebars – Template Injection And Remote Code Execution On Versions Under 4.6.0
-
Handlebars – Remote-code-execution Exploits Where Misusing prototype-builtins On Versions Under 4.5.3
-
Handlebars – Remote-code-execution Exploits Where Misusing The Helper blockHelperMissing On Versions Under 4.3.0
-
Handlebars – Prototype Pollution Vulnerability On Versions Greater Than Or Equal To 4.0.0 And Less Than 4.0.14
-
Handlebars – Prototype Pollution Vulnerability On Versions Greater Than Or Equal To 3.0.0 And Less Than 3.0.7
-
Handlebars – Prototype Pollution Vulnerability On Versions Between 4.0.14 And 4.1.2
-
Handlebars – Prototype Pollution Vulnerability On Versions Under 4.0.14
-
Handlebars – XSS Vulnerability On Versions Under 4.0.0
-
Vue. Possible XSS Vector On Versions Under 2.4.3
-
Vue. Potential XSS In SSR When Using v-bind On Versions Under 2.5.17
-
Vue. vue-server-renderer’s Dependency Of serialize-javascript To 2.1.2 On Versions Under 2.6.11
-
React. Potential XSS Vulnerability When Using User Data As A Key. This Only Affects v0.5.x And v0.4.x
-
React. XSS Via A Spoofed React Element On Versions Under 0.14.0
-
React. XSS Via A Spoofed React Element On Versions Under 0.14.0
-
AngularJS – XSS Vulnerability On Versions Under 1.8.0, Via Nested Option In Select Elements
-
React. Potential XSS Vulnerability When Using User Data As A Key. This Only Affects v0.5.x And v0.4.x
-
Vue. vue-server-renderer’s Dependency Of serialize-javascript To 2.1.2 On Versions Under 2.6.11
-
Vue. Potential XSS In SSR When Using v-bind On Versions Under 2.5.17
-
Vue. Possible XSS Vector On Versions Under 2.4.3
-
Handlebars – XSS Vulnerability On Versions Under 4.0.0
-
Handlebars – Prototype Pollution Vulnerability On Versions Under 4.0.14
-
Handlebars – Prototype Pollution Vulnerability On Versions Between 4.0.14 And 4.1.2
-
Handlebars – Prototype Pollution Vulnerability On Versions Greater Than Or Equal To 3.0.0 And Less Than 3.0.7
-
Handlebars – Prototype Pollution Vulnerability On Versions Greater Than Or Equal To 4.0.0 And Less Than 4.0.14
-
Handlebars – Remote-code-execution Exploits Where Misusing The Helper blockHelperMissing On Versions Under 4.3.0