CVE-2015-1270
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.
- Affected products
- Alt Linux, Google Chrome, International Components For Unicode, Opera, Red Hat, Suse, Ubuntu
- Google Chrome
- ≤ 43.0.2357.134
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-19
- NVD status
- Modified
- Published
- 2015-07-23
CVE-2015-1270 at NVD
No indexed exploits for CVE-2015-1270 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-1270 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.