7.5

CVE-2014-8146

Exploit

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

Data is provided by the National Vulnerability Database (NVD)
AppleiTunes Version <= 12.1.3
AppleiPhone OS Version <= 8.2
ApplemacOS X Version <= 10.10.4
ApplewatchOS Version <= 1.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 40.13% 0.972
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://bugs.icu-project.org/trac/changeset/37162
Vendor Advisory
Issue Tracking
http://seclists.org/fulldisclosure/2015/May/14
Third Party Advisory
Exploit
Mailing List
http://www.kb.cert.org/vuls/id/602540
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/74457
Third Party Advisory
VDB Entry