CVE-2014-9714: XSS
Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddxserializevalue function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9714?
CVE-2014-9714 has been classified as a medium severity vulnerability.
How do I fix CVE-2014-9714?
To fix CVE-2014-9714, upgrade the HipHop Virtual Machine to version 3.5.0 or later.
What are the potential impacts of CVE-2014-9714?
CVE-2014-9714 allows remote attackers to perform cross-site scripting attacks, potentially compromising user data.
Which version of HipHop Virtual Machine is affected by CVE-2014-9714?
CVE-2014-9714 affects all versions of HipHop Virtual Machine prior to 3.5.0, including 3.4.2.
Can CVE-2014-9714 be exploited without user interaction?
Yes, CVE-2014-9714 can be exploited by an attacker sending a crafted string to a vulnerable application, requiring no user interaction.