7.5
CVSSv2

CVE-2014-1716

Published: 09/04/2014 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome prior to 34.0.1847.116, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 8.0

debian debian linux 7.0

opensuse opensuse 12.3

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #773671 libv8-314: multiple security issues Package: src:libv8-314; Maintainer for src:libv8-314 is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 21 Dec 2014 20:21:07 UTC Severity: serious Tags: j ...