Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown
CVE-2016-10578
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
0
Attacker Value
Unknown
CVE-2017-17484
Disclosure Date: December 10, 2017 (last updated November 26, 2024)
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
0
Attacker Value
Unknown
CVE-2017-14952
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
0
Attacker Value
Unknown
CVE-2014-9654
Disclosure Date: April 24, 2017 (last updated November 26, 2024)
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
0
Attacker Value
Unknown
CVE-2017-7867
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.
0
Attacker Value
Unknown
CVE-2017-7868
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.
0
Attacker Value
Unknown
CVE-2014-9911
Disclosure Date: January 04, 2017 (last updated November 25, 2024)
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call.
0
Attacker Value
Unknown
CVE-2016-7415
Disclosure Date: September 17, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.
0
Attacker Value
Unknown
CVE-2016-6293
Disclosure Date: July 25, 2016 (last updated November 08, 2023)
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
0
Attacker Value
Unknown
CVE-2015-5922
Disclosure Date: October 09, 2015 (last updated October 05, 2023)
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.
0