CVE-2014-7926

EUVD-2014-7776
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux_desktop_supplementary
6.0
redhatenterprise_linux_server_supplementary
6.0
redhatenterprise_linux_server_supplementary_eus
6.6.z:z
redhatenterprise_linux_workstation_supplementary
6.0
opensuseopensuse
13.1
opensuseopensuse
13.2
googlechrome
𝑥
≤ 40.0.2214.85
oraclecommunications_messaging_server
7.0.5
oraclecommunications_messaging_server
8.0
icu-projectinternational_components_for_unicode
𝑥
< 55.1
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icu
bookworm
72.1-3
fixed
bullseye
67.1-7
fixed
sid
72.1-5
fixed
trixie
72.1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
ignored
trusty
Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068
released
utopic
Fixed 40.0.2214.94-0ubuntu0.14.10.1.1110
released
vivid
Fixed 40.0.2214.94-0ubuntu1.1120
released
wily
Fixed 40.0.2214.94-0ubuntu1.1120
released
icu
lucid
ignored
precise
Fixed 4.8.1.1-3ubuntu0.3
released
trusty
Fixed 52.1-3ubuntu0.2
released
utopic
Fixed 52.1-6ubuntu0.2
released
vivid
not-affected
wily
not-affected
oxide-qt
lucid
dne
precise
dne
trusty
Fixed 1.4.2-0ubuntu0.14.04.1
released
utopic
Fixed 1.4.2-0ubuntu0.14.10.1
released
vivid
Fixed 1.4.2-0ubuntu1
released
wily
Fixed 1.4.2-0ubuntu1
released
Common Weakness Enumeration
References