Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-1701


The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.


Published

2014-03-16T14:06:45.350

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome ≤ 33.0.1750.146 Yes
Application google chrome 33.0.1750.0 Yes
Application google chrome 33.0.1750.1 Yes
Application google chrome 33.0.1750.2 Yes
Application google chrome 33.0.1750.3 Yes
Application google chrome 33.0.1750.4 Yes
Application google chrome 33.0.1750.5 Yes
Application google chrome 33.0.1750.6 Yes
Application google chrome 33.0.1750.7 Yes
Application google chrome 33.0.1750.8 Yes
Application google chrome 33.0.1750.9 Yes
Application google chrome 33.0.1750.10 Yes
Application google chrome 33.0.1750.11 Yes
Application google chrome 33.0.1750.12 Yes
Application google chrome 33.0.1750.13 Yes
Application google chrome 33.0.1750.14 Yes
Application google chrome 33.0.1750.15 Yes
Application google chrome 33.0.1750.16 Yes
Application google chrome 33.0.1750.18 Yes
Application google chrome 33.0.1750.19 Yes
Application google chrome 33.0.1750.20 Yes
Application google chrome 33.0.1750.21 Yes
Application google chrome 33.0.1750.22 Yes
Application google chrome 33.0.1750.23 Yes
Application google chrome 33.0.1750.24 Yes
Application google chrome 33.0.1750.25 Yes
Application google chrome 33.0.1750.26 Yes
Application google chrome 33.0.1750.27 Yes
Application google chrome 33.0.1750.28 Yes
Application google chrome 33.0.1750.29 Yes
Application google chrome 33.0.1750.30 Yes
Application google chrome 33.0.1750.31 Yes
Application google chrome 33.0.1750.34 Yes
Application google chrome 33.0.1750.35 Yes
Application google chrome 33.0.1750.36 Yes
Application google chrome 33.0.1750.37 Yes
Application google chrome 33.0.1750.38 Yes
Application google chrome 33.0.1750.39 Yes
Application google chrome 33.0.1750.40 Yes
Application google chrome 33.0.1750.41 Yes
Application google chrome 33.0.1750.42 Yes
Application google chrome 33.0.1750.43 Yes
Application google chrome 33.0.1750.44 Yes
Application google chrome 33.0.1750.45 Yes
Application google chrome 33.0.1750.46 Yes
Application google chrome 33.0.1750.47 Yes
Application google chrome 33.0.1750.48 Yes
Application google chrome 33.0.1750.49 Yes
Application google chrome 33.0.1750.50 Yes
Application google chrome 33.0.1750.51 Yes
Application google chrome 33.0.1750.52 Yes
Application google chrome 33.0.1750.53 Yes
Application google chrome 33.0.1750.54 Yes
Application google chrome 33.0.1750.55 Yes
Application google chrome 33.0.1750.56 Yes
Application google chrome 33.0.1750.57 Yes
Application google chrome 33.0.1750.58 Yes
Application google chrome 33.0.1750.59 Yes
Application google chrome 33.0.1750.60 Yes
Application google chrome 33.0.1750.61 Yes
Application google chrome 33.0.1750.62 Yes
Application google chrome 33.0.1750.63 Yes
Application google chrome 33.0.1750.64 Yes
Application google chrome 33.0.1750.65 Yes
Application google chrome 33.0.1750.66 Yes
Application google chrome 33.0.1750.67 Yes
Application google chrome 33.0.1750.68 Yes
Application google chrome 33.0.1750.69 Yes
Application google chrome 33.0.1750.70 Yes
Application google chrome 33.0.1750.71 Yes
Application google chrome 33.0.1750.73 Yes
Application google chrome 33.0.1750.74 Yes
Application google chrome 33.0.1750.75 Yes
Application google chrome 33.0.1750.76 Yes
Application google chrome 33.0.1750.77 Yes
Application google chrome 33.0.1750.79 Yes
Application google chrome 33.0.1750.80 Yes
Application google chrome 33.0.1750.81 Yes
Application google chrome 33.0.1750.82 Yes
Application google chrome 33.0.1750.83 Yes
Application google chrome 33.0.1750.85 Yes
Application google chrome 33.0.1750.88 Yes
Application google chrome 33.0.1750.89 Yes
Application google chrome 33.0.1750.90 Yes
Application google chrome 33.0.1750.91 Yes
Application google chrome 33.0.1750.92 Yes
Application google chrome 33.0.1750.93 Yes
Application google chrome 33.0.1750.104 Yes
Application google chrome 33.0.1750.106 Yes
Application google chrome 33.0.1750.107 Yes
Application google chrome 33.0.1750.108 Yes
Application google chrome 33.0.1750.109 Yes
Application google chrome 33.0.1750.110 Yes
Application google chrome 33.0.1750.111 Yes
Application google chrome 33.0.1750.112 Yes
Application google chrome 33.0.1750.113 Yes
Application google chrome 33.0.1750.115 Yes
Application google chrome 33.0.1750.116 Yes
Application google chrome 33.0.1750.117 Yes
Application google chrome 33.0.1750.124 Yes
Application google chrome 33.0.1750.125 Yes
Application google chrome 33.0.1750.126 Yes
Application google chrome 33.0.1750.132 Yes
Application google chrome 33.0.1750.133 Yes
Application google chrome 33.0.1750.135 Yes
Application google chrome 33.0.1750.136 Yes
Application google chrome 33.0.1750.144 Yes

References