Skip to main content

Vendor/product archive

yahoo / yui CVEs

Beta · best-effort

12 CVEs tagged to yahoo / yui0 Critical, 0 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2013-6780

Published Nov 13, 2013

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4942

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4941

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4940

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4939

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5883

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5882

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5881

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4710

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4209

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4208

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4207

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1