CVE-2014-1716
published 2014-04-09CVE-2014-1716: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.93%
78.0th percentile
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 34.0.1847.115 | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome 34.0.1847.115 V8 Handler runtime.cc runtime_setprototype code injection (Nessus ID 73431 / ID 166973)
vuldb·2026-05-10·CVSS 7.5
CVE-2014-1716 [HIGH] Google Chrome 34.0.1847.115 V8 Handler runtime.cc runtime_setprototype code injection (Nessus ID 73431 / ID 166973)
A vulnerability was found in Google Chrome 34.0.1847.115. It has been classified as problematic. This vulnerability affects the function runtime_setprototype of the file runtime.cc of the component V8 Handler. The manipulation leads to code injection.
This vulnerability is listed as CVE-2014-1716. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-r863-653f-pw4g: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime
ghsa_unreviewed·2022-05-14
CVE-2014-1716 [HIGH] CWE-94 GHSA-r863-653f-pw4g: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
OSV
CVE-2014-1716: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime
osv·2014-04-09·CVSS 7.5
CVE-2014-1716 [HIGH] CVE-2014-1716: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Red Hat
v8: cross-site scripting flaw in Runtime_SetPrototype()
vendor_redhat·2014-03-20·CVSS 7.5
CVE-2014-1716 [HIGH] CWE-79 v8: cross-site scripting flaw in Runtime_SetPrototype()
v8: cross-site scripting flaw in Runtime_SetPrototype()
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Package: ruby193-v8 (CloudForms Management Engine 5) - Not affected
Package: ruby193-v8 (OpenShift Enterprise 1) - Not affected
Package: v8 (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 3) - Not affected
Package: v8 (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat Satellite
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=354123https://code.google.com/p/v8/source/detail?r=20138http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=354123https://code.google.com/p/v8/source/detail?r=20138
2014-04-09
Published