CVE-2014-9911 PUBLISHED

Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call.

EPSS 1.80% · 82.7th percentile

Risk Scores

EPSS Score
1.80%
82.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSicu0, 4.8.1.1-12ubuntu2, 4.8.1.1-13+nmu1
Ubuntu:16.04:LTSmozjs2424.2.0-3ubuntu2.1, 0, 24.2.0-3ubuntu1
Ubuntu:16.04:LTSandroid20160330-0939-0ubuntu1, 0, 20150818-1500-0ubuntu2

Timeline

References

Open in Interactive Console →