CVE-2016-6293
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
- Affected products
- International Components For Unicode, Suse, Ubuntu
- Icu-project International Components For Unicode
- ≤ 57.1
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 5.0% (91th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2016-07-25
CVE-2016-6293 at NVD
No indexed exploits for CVE-2016-6293 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2016-6293 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.