Angularjs
angularjs
27 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Angularjs Fedoraproject2Angularjs FedoraJun 17, 2026 Mar 30, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulne...Show more |
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer br...Show more |
2Angular Angularjs2Angular AngularjsJun 17, 2026 May 26, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the a...Show more |
3Angularjs FedoraprojectNetapp3Angularjs FedoraOntap Select Deploy Administration UtilityJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PA...Show more |
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leadin...Show more |
2Angularjs Redhat3Angularjs Decision ManagerProcess AutomationJun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, with...Show more |
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload. |