Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
References
Link Providers
https://www.spirityenterprise.com/pentest spirity
http://bugs.jqueryui.com/ticket/6016 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0442.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-1462.html cve-icon cve-icon
http://seclists.org/oss-sec/2014/q4/613 cve-icon cve-icon
http://seclists.org/oss-sec/2014/q4/616 cve-icon cve-icon
http://www.debian.org/security/2015/dsa-3249 cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html cve-icon cve-icon
http://www.securityfocus.com/bid/71106 cve-icon cve-icon
http://www.securitytracker.com/id/1037035 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/98696 cve-icon cve-icon
https://github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3 cve-icon cve-icon
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2022/01/msg00014.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-5312 cve-icon
https://security.netapp.com/advisory/ntap-20190416-0007/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-5312 cve-icon
https://www.drupal.org/sa-core-2022-002 cve-icon cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.02665}

epss

{'score': 0.02055}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T04:17:10.323Z

Reserved: 2014-11-14T00:00:00

Link: CVE-2010-5312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-11-24T16:59:00.087

Modified: 2025-04-12T10:46:40.837

Link: CVE-2010-5312

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-09-03T00:00:00Z

Links: CVE-2010-5312 - Bugzilla