jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.
We have discovered 25,023 live websites that are affected by CVE-2016-10707.
Product | |
Category | JavaScript Frameworks |
Vulnerable Domains | 25,023 live websites (0.13% of jQuery install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 1 versions ( 0.32% of all versions) |
![]() | 7,090 websites |
![]() | 3,210 websites |
![]() | 1,904 websites |
![]() | 1,855 websites |
![]() | 1,578 websites |
![]() | 1,517 websites |
![]() | 1,161 websites |
![]() | 767 websites |
![]() | 497 websites |
![]() | 378 websites |
.com | 9,226 websites |
.cz | 3,041 websites |
.nl | 1,793 websites |
.ru | 880 websites |
.de | 806 websites |
.org | 640 websites |
.net | 620 websites |
.fr | 564 websites |
.jp | 560 websites |
.co.uk | 464 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.***.pl | ![]() | **,***,*** | |
*******.***.pl | ![]() | **,***,*** | |
*******.********.pl | ![]() | **,***,*** | |
********.com | ![]() | **,***,*** | |
***.*****.pl | ![]() | **,***,*** | |
*****.****.pl | ![]() | **,***,*** | |
*************.com | ![]() | **,***,*** | |
***.*******.***.pl | ![]() | **,***,*** | |
***.*******.***.pl | ![]() | **,***,*** | |
**.********.pl | ![]() | **,***,*** | |
**.********.pl | ![]() | **,***,*** | |
*************.***.pl | ![]() | **,***,*** | |
************.pl | ![]() | **,***,*** | |
****************.***.pl | ![]() | **,***,*** | |
********.pl | ![]() | **,***,*** | |
********************.pl | ![]() | **,***,*** | |
***********.pl | ![]() | **,***,*** | |
*********.******.***.pl | ![]() | **,***,*** | |
************.pl | ![]() | **,***,*** | |
*****.*******.eu | ![]() | **,***,*** |