Home/Product/icu project international components for unicode
Product

icu project international components for unicode

23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5222
< 77.1
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' stru
7.0HIGH
CVE-2020-21913
< 66.1
International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssembl
5.5MEDIUM
CVE-2020-10531
<= 66.1
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a he
8.8HIGH
CVE-2018-18928
all versions
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificSt
9.8CRITICAL
CVE-2017-15396
< 60.2
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in G
6.5MEDIUM
CVE-2017-15422
< 60.1
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8
6.5MEDIUM
CVE-2017-17484
<= 60.1
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv
9.8CRITICAL
CVE-2017-14952
<= 59.1
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to e
9.8CRITICAL
CVE-2014-9654
< 55.1
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrom
9.8CRITICAL
CVE-2017-7868
<= 58.2
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer ov
7.5HIGH
CVE-2017-7867
<= 58.2
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer ov
7.5HIGH
CVE-2014-9911
< 54.1
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unico
9.8CRITICAL
CVE-2016-7415
<= 57.1
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for
9.8CRITICAL
CVE-2016-6293
<= 57.1
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ d
9.8CRITICAL
CVE-2015-5922
< 53.1
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watc
CVE-2014-8147
< 55.1
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in Internation
CVE-2014-8146
< 55.1
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in Internation
CVE-2014-7940
<= 52.1
The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used
CVE-2014-7926
< 55.1
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chr
CVE-2014-7923
< 55.1
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chr
CVE-2011-4599
< 49.1
Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49
CVE-2007-4771
<= 3.8.1
Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.
CVE-2007-4770
<= 3.8.1
libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent captu
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin