CVE-2016-10707

jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.


We have discovered 25,023 live websites that are affected by CVE-2016-10707.

Run a Free Instant Scan




Affected Software

Product  jQuery
Category JavaScript Frameworks
Vulnerable Domains25,023 live websites (0.13% of jQuery install base)
Vulnerable Versions
  • from 3 through 3
Vulnerable Versions Count1 versions ( 0.32% of all versions)



Details

  • Published - Jan 19, 2018
  • Updated - Aug 6, 2024

CVE-2016-10707 usage by Country

United States7,090 websites



Czech Republic3,210 websites
Netherlands1,904 websites
Japan1,855 websites
Germany1,578 websites
France1,517 websites
Russia1,161 websites
China767 websites
GB497 websites
Brazil378 websites

CVE-2016-10707 usage by TLD

.com9,226 websites
.cz3,041 websites
.nl1,793 websites
.ru880 websites
.de806 websites
.org640 websites
.net620 websites
.fr564 websites
.jp560 websites
.co.uk464 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-10707

Top websites that are affected by CVE-2016-10707. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***.pl Poland**,***,***
*******.***.pl Poland**,***,***
*******.********.pl Poland**,***,***
********.com Poland**,***,***
***.*****.pl Poland**,***,***
*****.****.pl Poland**,***,***
*************.com Poland**,***,***
***.*******.***.pl Poland**,***,***
***.*******.***.pl Poland**,***,***
**.********.pl Poland**,***,***
**.********.pl Poland**,***,***
*************.***.pl Poland**,***,***
************.pl Poland**,***,***
****************.***.pl Poland**,***,***
********.pl Poland**,***,***
********************.pl Poland**,***,***
***********.pl Poland**,***,***
*********.******.***.pl Poland**,***,***
************.pl Poland**,***,***
*****.*******.eu Poland**,***,***
See full domain list

FAQ

A total of 25,023 websites have been identified as vulnerable to CVE-2016-10707, based on global website indexing conducted by WebTechSurvey.
The jQuery is affected by the CVE-2016-10707 vulnerability.
jQuery versions up to and including 3 are vulnerable to CVE-2016-10707.