CVE-2014-1869
EPSS 2.8%
Description
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
How to fix CVE-2014-1869
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/db4o—no fix listed
Is CVE-2014-1869 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0