Total vulnerabilities in the database
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
Software | From | Fixed in |
---|---|---|
microsoft / lync | 2010 | 2010.x |
microsoft / office_communicator | 2007-r2 | 2007-r2.x |
microsoft / internet_explorer | 8 | 8.x |
microsoft / internet_explorer | 9 | 9.x |