Search CVE reports


Toggle filters

41 – 42 of 42 results


CVE-2019-14863

Low priority
Fixed

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

1 affected package

angular.js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-10768

Low priority
Vulnerable

In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.

1 affected package

angular.js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Not affected Not affected Not affected Not affected Vulnerable
Show less packages