CVE-2014-9654

The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 40.0.2214.85
icu-projectinternational_components_for_unicode
𝑥
< 55.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icu
bookworm
72.1-3
fixed
bullseye
67.1-7
fixed
sid
72.1-5
fixed
trixie
72.1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icu
lucid
ignored
precise
Fixed 4.8.1.1-3ubuntu0.3
released
trusty
Fixed 52.1-3ubuntu0.2
released
utopic
Fixed 52.1-6ubuntu0.2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libicu-doc
suse enterprise sap 12
52.1-7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-7.1
fixed
suse enterprise server 12 SP1
52.1-7.1
fixed
suse enterprise server 12 SP2
52.1-7.1
fixed
suse enterprise server 12 SP3
52.1-7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1
suse enterprise sap 12
52.1-7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-7.1
fixed
suse enterprise server 12 SP1
52.1-7.1
fixed
suse enterprise server 12 SP2
52.1-7.1
fixed
suse enterprise server 12 SP3
52.1-7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1-32bit
suse enterprise sap 12
52.1-7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-7.1
fixed
suse enterprise server 12 SP1
52.1-7.1
fixed
suse enterprise server 12 SP2
52.1-7.1
fixed
suse enterprise server 12 SP3
52.1-7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1-data
suse enterprise sap 12
52.1-7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-7.1
fixed
suse enterprise server 12 SP1
52.1-7.1
fixed
suse enterprise server 12 SP2
52.1-7.1
fixed
suse enterprise server 12 SP3
52.1-7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
chromium-browser
RHEL 6
0:40.0.2214.91-1.el6_6
fixed