CVE-2010-4209
Yahoo Yui - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
References (14)
Scores
EPSS
0.0277
EPSS Percentile
85.9%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
yahoo/yui
yahoo/yui
n/a/n/a
Timeline
Published
Nov 07, 2010
Tracked Since
Feb 18, 2026