CVE-2014-1701

Blink <33.0.1750.149 - XSS

Title source: llm

Description

The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

Scores

EPSS 0.0036
EPSS Percentile 58.0%

Details

CWE
CWE-79
Status published
Products (50)
google/chrome < 33.0.1750.146
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
... and 40 more
Published Mar 16, 2014
Tracked Since Feb 18, 2026