Sploitus

CVE-2014-8146

2 known exploits for CVE-2014-8146

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

Affected products
Icu, Suse, Ubuntu, Itunes
Apple Itunes
≤ 12.1.3
Apple Iphone Os
≤ 8.2
Apple Mac Os X
≤ 10.10.4
Apple Watchos
≤ 1.0.1
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
24.5% (98th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2015-05-25
CVE-2014-8146 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2014-8146

Proof-of-concept code and exploit modules indexed by Sploitus