CVE-2014-7940
The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.
- Affected products
- Alt Linux, Google Chrome, International Components For Unicode, Red Hat, Suse, Ubuntu
- Google Chrome
- ≤ 40.0.2214.85
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2015-01-22
CVE-2014-7940 at NVD
No indexed exploits for CVE-2014-7940 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2014-7940 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.