Medium severity6.1NVD Advisory· Published Nov 24, 2014· Updated May 6, 2026
CVE-2010-5312
CVE-2010-5312
Description
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jquery-uinpm | >= 1.7.0, < 1.10.0 | 1.10.0 |
org.webjars.npm:jquery-uiMaven | >= 1.7.0, < 1.10.0 | 1.10.0 |
jQuery.UI.CombinedNuGet | >= 1.7.0, < 1.10.0 | 1.10.0 |
jquery-ui-railsRubyGems | < 4.0.0 | 4.0.0 |
Affected products
8- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Patches
17e9060c109b9Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
32- www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlnvdPatchThird Party AdvisoryWEB
- bugs.jqueryui.com/ticket/6016nvdExploitVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-0442.htmlnvdThird Party AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-1462.htmlnvdThird Party AdvisoryWEB
- seclists.org/oss-sec/2014/q4/613nvdMailing ListThird Party AdvisoryWEB
- seclists.org/oss-sec/2014/q4/616nvdMailing ListThird Party AdvisoryWEB
- www.debian.org/security/2015/dsa-3249nvdThird Party AdvisoryWEB
- www.securityfocus.com/bid/71106nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037035nvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/98696nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-wcm2-9c89-wmfmghsaADVISORY
- github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3nvdVendor AdvisoryWEB
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EnvdMailing ListThird Party AdvisoryWEB
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EnvdMailing ListThird Party AdvisoryWEB
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/nvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2010-5312ghsaADVISORY
- security.netapp.com/advisory/ntap-20190416-0007/nvdThird Party Advisory
- www.drupal.org/sa-core-2022-002nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-ui-rails/CVE-2010-5312.ymlghsaWEB
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3EghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4ghsaWEB
- security.netapp.com/advisory/ntap-20190416-0007ghsaWEB
- web.archive.org/web/20150316023043/http://www.securityfocus.com/bid/71106ghsaWEB
- web.archive.org/web/20170316161850/http://www.securitytracker.com/id/1037035ghsaWEB
News mentions
0No linked articles in our index yet.