Javascript Exploits

229 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2223 EXPLOITDB javascript VERIFIED
Microsoft XML Core Services 3.0-6.0 - Remote Code Execution via substringData Integer Overflow
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
by anonymous
CVE-2007-2843 EXPLOITDB javascript VERIFIED
Apple Safari 2.0.4 - Info Disclosure
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
by Gareth Heyes
CVE-2007-2580 EXPLOITDB javascript VERIFIED
Apple Safari - Unprotected Keychain Password Exposure via JavaScript Parameter
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.
by poplix
CVE-2006-4449 EXPLOITDB javascript VERIFIED
MyBulletinBoard 1.1.7 - Cross-Site Scripting via GIF Image with URL-Encoded JavaScript
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript, which is rendered by Internet Explorer.
by Redworm