← All CVEs

CVE-2014-8146

high · 7.5

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

7.5
CVSS
24.3%
EPSS (exploit prob.)
98th
EPSS percentile
2015-05-25
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
appleitunes<= 12.1.3
appleiphone_os<= 8.2
applemac_os_x<= 10.10.4
applewatchos<= 1.0.1
icu-projectinternational_components_for_unicode< 55.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8146