CVE-2014-1716: Debian Linux

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Google Chrome: up to and including 34.0.1847.115
  • Opensuse Opensuse: version 12.3 only; version 13.1 only

Published 2014-04-09. Last modified 2026-06-17.