Description
The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2883-1 | chromium-browser security update |
EUVD |
EUVD-2014-1775 | The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events. |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T09:50:11.316Z
Reserved: 2014-01-29T00:00:00.000Z
Link: CVE-2014-1701
No data.
Status : Deferred
Published: 2014-03-16T14:06:45.350
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-1701
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD