CVE-2016-7103: Debian Linux
Medium severity, CVSS 6.1. EPSS: 22.6% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 35 only; version 36 only
- Jqueryui jQuery UI: from 1.10.0, up to and including 1.11.4
- Juniper Junos: version 21.2 only
- Netapp Snapcenter: affected versions not specified
- Oracle Application Express: before 19.1 (fixed in 19.1)
- Oracle Business Intelligence: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Hospitality Cruise Fleet Management: version 9.0.11 only
- Oracle OSS Support Tools: before 2.12.42 (fixed in 2.12.42); version 2.12.42 only
- Oracle Primavera Unifier: from 16.0, up to and including 16.2; from 17.0, up to and including 17.12.4; from 18.0, up to and including 18.8.4
- Oracle Siebel UI Framework: up to and including 21.2
- Oracle WebLogic Server: version 10.3.6.0.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Red Hat Openstack: version 7.0 only; version 8 only; version 9 only
Published 2017-03-15. Last modified 2026-06-17.