📦

ui_library

Vendor: yahoo

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 1.10% Exploit Prob.
Latest CVE CVE-2007-2385 Apr 30

Security Vulnerability Index

Page 1 / 1
5.0 CVSS

The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

EPSS: 1.10%