UBUNTU-CVE-2014-1747

Source
https://ubuntu.com/security/CVE-2014-1747
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1747.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-1747
Upstream
  • CVE-2014-1747
Published
2014-05-21T11:14:00Z
Modified
2025-09-08T16:43:08Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

References

Affected packages

Ubuntu:14.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser@36.0.1985.125-0ubuntu1.14.04.0~pkg1029?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
36.0.1985.125-0ubuntu1.14.04.0~pkg1029

Affected versions

29.*
29.0.1547.65-0ubuntu2
31.*
31.0.1650.63-0ubuntu1~20131204.1
32.*
32.0.1700.107-0ubuntu1~20140204.977.1
33.*
33.0.1750.152-0ubuntu1~pkg995.1
34.*
34.0.1847.116-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
            "binary_name": "chromium-browser"
        },
        {
            "binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
            "binary_name": "chromium-browser-l10n"
        },
        {
            "binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
            "binary_name": "chromium-chromedriver"
        },
        {
            "binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
            "binary_name": "chromium-codecs-ffmpeg"
        },
        {
            "binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
            "binary_name": "chromium-codecs-ffmpeg-extra"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1747.json"