CVE-2014-1716 PUBLISHED

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

EPSS 1.07% · 77.6th percentile

Risk Scores

EPSS Score
1.07%
77.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibv8-3.140, 3.14.5.8-11ubuntu1
Ubuntu:16.04:LTSlibv8-3.140, 3.14.5.8-5ubuntu2

Timeline

References

Open in Interactive Console →