Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Marked | Marked_project | * | 0.3.2 (including) |
| Node-marked | Ubuntu | artful | * |
| Node-marked | Ubuntu | esm-apps/xenial | * |
| Node-marked | Ubuntu | trusty | * |
| Node-marked | Ubuntu | upstream | * |
| Node-marked | Ubuntu | utopic | * |
| Node-marked | Ubuntu | vivid | * |
| Node-marked | Ubuntu | wily | * |
| Node-marked | Ubuntu | xenial | * |
| Node-marked | Ubuntu | yakkety | * |
| Node-marked | Ubuntu | zesty | * |