7.5
CVSSv2

CVE-2014-7940

Published: 22/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome prior to 40.0.2214.91, does not initialize memory for a data structure, which allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

icu-project international components for unicode

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic Updated chromium-browser packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having Important securityi ...
Debian Bug report logs - #776719 icu: CVE-2015-1205 / CVE-2014-9654 Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sat, 31 Jan 2015 17:00:11 UTC Severity: serious Tags: patch, security Fixed in version icu/521-71 Done ...
Debian Bug report logs - #780503 icu: incomplete fix for CVE-2014-7940 Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 15 Mar 2015 01:51:02 UTC Severity: serious Tags: patch, security Found in version icu/521-71 Fi ...
Debian Bug report logs - #776264 icu: CVE-2014-6585 out-of-bounds read Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Mon, 26 Jan 2015 02:30:02 UTC Severity: important Tags: patch Found in version icu/521-7 Fixed in ver ...
Debian Bug report logs - #776265 icu: multiple security issues Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Mon, 26 Jan 2015 02:39:02 UTC Severity: important Tags: patch, security Found in version icu/521-7 Fixed in v ...
ICU could be made to crash or run programs as your login if it processed specially crafted data ...
Several security issues were fixed in Oxide ...
ICU could be made to crash or run programs as your login if it processed specially crafted data ...
USN-2522-1 introduced a regression in ICU ...
The collator implementation in i18n/ucolcpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 400221491, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequenc ...