jquery-ui: XSS vulnerability in default content in Tooltip widget
Published Nov 24, 2014
4.3
MEDIUMCVSS 2.0
EPSS 6.46%
Description
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
Affected products
No data.
Configuration 1
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 6
ipa-0:3.0.0-47.el6
Fixed · RHSA-2015:1462
Red Hat Enterprise Linux 7
ipa-0:4.1.0-18.el7
Fixed · RHSA-2015:0442
CloudForms Management Engine 5
ruby193-rubygem-jquery-rails
Will not fix
OpenShift Enterprise 1
ruby193-rubygem-jquery-rails
Will not fix
OpenStack Foreman
ruby193-rubygem-jquery-ui-rails
Will not fix
Red Hat Enterprise Linux 6
python-sphinx
Will not fix
Red Hat Enterprise Linux 7
python-sphinx
Will not fix
Red Hat Enterprise Linux 7
yelp-xsl
Will not fix
Red Hat OpenShift Enterprise 2
ruby193-rubygem-jquery-rails
Will not fix
Red Hat OpenStack Platform 4
ruby193-rubygem-jquery-rails
Will not fix
Red Hat Satellite 6
ruby193-rubygem-jquery-ui-rails
Will not fix
Red Hat Software Collections
ror40-rubygem-jquery-rails
Will not fix
Red Hat Software Collections
ruby193-rubygem-jquery-rails
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygem-jquery-rails
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ipa-0:3.0.0-47.el6 | Fixed | RHSA-2015:1462 |
| Red Hat Enterprise Linux 7 | ipa-0:4.1.0-18.el7 | Fixed | RHSA-2015:0442 |
| CloudForms Management Engine 5 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| OpenShift Enterprise 1 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| OpenStack Foreman | ruby193-rubygem-jquery-ui-rails | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-sphinx | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | python-sphinx | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | yelp-xsl | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat OpenStack Platform 4 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Satellite 6 | ruby193-rubygem-jquery-ui-rails | Will not fix | n/a |
| Red Hat Software Collections | ror40-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Software Collections | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-jquery-rails | Will not fix | n/a |
jquery-ui
npm
Introduced 0 Fixed 1.10.0jquery-ui-rails
RubyGems
Introduced 0 Fixed 4.0.0org.webjars.npm:jquery-ui
Maven
Introduced 0 Fixed 1.10.0jQuery.UI.Combined
NuGet
Introduced 0 Fixed 1.10.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jquery-ui | 0 | 1.10.0 |
| RubyGems | jquery-ui-rails | 0 | 4.0.0 |
| Maven | org.webjars.npm:jquery-ui | 0 | 1.10.0 |
| NuGet | jQuery.UI.Combined | 0 | 1.10.0 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (39 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.46% (0.06463) | 93.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.46% (0.06463) | 92.84th | v5 (v2026.06.15) |
| Mar 4, 2026 | 7.05% (0.07046) | 91.32th | v4 (v2025.03.14) |
| Mar 1, 2026 | 3.49% (0.03486) | 87.40th | v4 (v2025.03.14) |
| Feb 4, 2026 | 7.35% (0.07349) | 91.48th | v4 (v2025.03.14) |
| Feb 1, 2026 | 3.44% (0.03441) | 87.23th | v4 (v2025.03.14) |
| Jan 4, 2026 | 7.35% (0.07349) | 91.42th | v4 (v2025.03.14) |
| Jan 1, 2026 | 3.44% (0.03441) | 87.19th | v4 (v2025.03.14) |
| Dec 4, 2025 | 7.35% (0.07349) | 91.34th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.44% (0.03441) | 87.13th | v4 (v2025.03.14) |
| Nov 4, 2025 | 7.35% (0.07349) | 91.28th | v4 (v2025.03.14) |
| Nov 1, 2025 | 3.44% (0.03441) | 87.04th | v4 (v2025.03.14) |
| Oct 9, 2025 | 7.35% (0.07349) | 91.23th | v4 (v2025.03.14) |
| Oct 8, 2025 | 9.21% (0.09215) | 92.31th | v4 (v2025.03.14) |
| Oct 4, 2025 | 6.28% (0.06276) | 90.55th | v4 (v2025.03.14) |
| Oct 1, 2025 | 2.78% (0.02781) | 85.57th | v4 (v2025.03.14) |
| Sep 4, 2025 | 6.44% (0.06437) | 90.70th | v4 (v2025.03.14) |
| Sep 1, 2025 | 3.38% (0.03377) | 86.98th | v4 (v2025.03.14) |
| Aug 28, 2025 | 7.54% (0.07545) | 91.44th | v4 (v2025.03.14) |
| Aug 4, 2025 | 6.28% (0.06276) | 90.56th | v4 (v2025.03.14) |
| Aug 1, 2025 | 2.78% (0.02781) | 85.59th | v4 (v2025.03.14) |
| Jul 4, 2025 | 6.15% (0.06154) | 90.38th | v4 (v2025.03.14) |
| Jul 1, 2025 | 2.89% (0.02887) | 85.78th | v4 (v2025.03.14) |
| Jun 4, 2025 | 6.15% (0.06154) | 90.33th | v4 (v2025.03.14) |
| Jun 1, 2025 | 2.89% (0.02887) | 85.72th | v4 (v2025.03.14) |
| May 4, 2025 | 6.15% (0.06154) | 90.29th | v4 (v2025.03.14) |
| May 1, 2025 | 2.89% (0.02887) | 85.61th | v4 (v2025.03.14) |
| Apr 8, 2025 | 6.15% (0.06154) | 89.93th | v4 (v2025.03.14) |
| Apr 7, 2025 | 2.89% (0.02887) | 85.15th | v4 (v2025.03.14) |
| Apr 3, 2025 | 6.15% (0.06154) | 89.91th | v4 (v2025.03.14) |
| Apr 2, 2025 | 2.89% (0.02887) | 85.13th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.15% (0.06154) | 90.12th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.26% (0.00260) | 66.27th | v3 (v2023.03.01) |
| Jul 6, 2024 | 0.26% (0.00260) | 66.00th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.25% (0.00252) | 64.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.25% (0.00252) | 61.25th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.96% (0.01955) | 78.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.96% (0.01955) | 76.59th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.96% (0.01955) | 55.71th | v2 (v2022.01.01) |
References (17)
- http://bugs.jqueryui.com/ticket/8859 x_refsource_CONFIRMIssue TrackingVendor Advisory
- http://bugs.jqueryui.com/ticket/8861 x_refsource_CONFIRMIssue TrackingVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0442.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1462.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/oss-sec/2014/q4/613 mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- http://seclists.org/oss-sec/2014/q4/616 mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/71107 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2012-6662 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1166064 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98697 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-qqxp-xp9v-vvx6 Advisory
- https://github.com/jquery/jquery-ui/commit/5fee6fd5000072ff32f2d65b6451f39af9e0e39e x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/jquery/jquery-ui/commit/f2854408cce7e4b7fc6bf8676761904af9c96bde x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/jquery/jquery/issues/2432 x_refsource_MISC
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-ui-rails/CVE-2012-6662.yml
- https://nvd.nist.gov/vuln/detail/CVE-2012-6662
- https://www.cve.org/CVERecord?id=CVE-2012-6662
Change history (0)
No recorded changes yet.