CVE-2014-1716: Code Injection
Cross-site scripting (XSS) vulnerability in the RuntimeSetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1716?
CVE-2014-1716 is considered a high severity vulnerability that allows remote attackers to perform Cross-site scripting (XSS) attacks.
How do I fix CVE-2014-1716?
To fix CVE-2014-1716, update Google Chrome to the latest version or apply the security patches provided for affected distributions.
What software is affected by CVE-2014-1716?
CVE-2014-1716 affects Google Chrome versions prior to 34.0.1847.116 and specific versions of Debian and openSUSE.
What type of vulnerability is CVE-2014-1716?
CVE-2014-1716 is a Cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
When was CVE-2014-1716 reported?
CVE-2014-1716 was reported in 2014 and affects multiple versions of Google Chrome and certain Linux distributions.