---
title: "CVE-2014-1716\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-1716?format=md
keywords: index, follow
---

# CVE-2014-1716

Publication date 9 April 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Cross-site scripting (XSS) vulnerability in the Runtime\_SetPrototype
function in runtime.cc in Google V8, as used in Google Chrome before
34.0.1847.116, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors, aka "Universal XSS (UXSS)."

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-1716?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Fixed 34.0.1847.116-0ubuntu~1.13.10.0~pkg991 |
| 12.10 quantal | Fixed 34.0.1847.116-0ubuntu~1.12.10.0~pkg900 |
| 12.04 LTS precise | Fixed 34.0.1847.116-0ubuntu~1.12.04.0~pkg884 |
| 10.04 LTS lucid | Ignored end of life |
| libv8 | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.10 utopic | Not in release |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| libv8-3.14 | 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Ignored end of standard support |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored end of standard support |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| oxide-qt | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| qtjsbackend-opensource-src | 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.10 utopic | Not in release |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [chrisccoulson](https://launchpad.net/~chrisccoulson)

Issue was fixed prior to Oxide r501, the first version to
be included in an Ubuntu release

---

### [mikesalvatore](https://launchpad.net/~mikesalvatore)

The Ubuntu Security Team does not support libv8

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1716)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-1716)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-1716)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-1716)

### Other references

* <https://code.google.com/p/v8/source/detail?r=20138>
* <https://code.google.com/p/chromium/issues/detail?id=354123>
* <http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html>
* <https://www.cve.org/CVERecord?id=CVE-2014-1716>
