CVE-2014-1747

Google Chrome <35.0.1916.114 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

Scores

EPSS 0.0042
EPSS Percentile 61.7%

Details

CWE
CWE-79
Status published
Products (50)
google/chrome < 35.0.1916.113
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
google/chrome
... and 40 more
Published May 21, 2014
Tracked Since Feb 18, 2026