Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown

CVE-2016-10578

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
0
Attacker Value
Unknown

CVE-2017-17484

Disclosure Date: December 10, 2017 (last updated November 26, 2024)
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
0
Attacker Value
Unknown

CVE-2017-14952

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
0
Attacker Value
Unknown

CVE-2014-9654

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
0
Attacker Value
Unknown

CVE-2017-7867

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.
0
Attacker Value
Unknown

CVE-2017-7868

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.
0
Attacker Value
Unknown

CVE-2014-9911

Disclosure Date: January 04, 2017 (last updated November 25, 2024)
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call.
0
Attacker Value
Unknown

CVE-2016-7415

Disclosure Date: September 17, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.
0
Attacker Value
Unknown

CVE-2016-6293

Disclosure Date: July 25, 2016 (last updated November 08, 2023)
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
0
Attacker Value
Unknown

CVE-2015-5922

Disclosure Date: October 09, 2015 (last updated October 05, 2023)
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.
0