Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1701

Опубликовано: 16 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

РелизСтатусПримечание
devel

released

33.0.1750.152-0ubuntu1~pkg995.1
lucid

ignored

end of life
precise

released

33.0.1750.152-0ubuntu0.12.04.1~pkg879.1
quantal

released

33.0.1750.152-0ubuntu0.12.10.1~pkg895.1
saucy

released

33.0.1750.152-0ubuntu0.13.10.1~pkg984.1
upstream

released

33.0.1750.149

Показывать по

РелизСтатусПримечание
devel

DNE

lucid

DNE

precise

DNE

quantal

DNE

saucy

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 58%
0.00362
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

debian
почти 12 лет назад

The GenerateFunction function in bindings/scripts/code_generator_v8.pm ...

github
больше 3 лет назад

The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

EPSS

Процентиль: 58%
0.00362
Низкий

4.3 Medium

CVSS2