CVE-2017-15422 PUBLISHED

Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

EPSS 3.85% · 88.1th percentile

Risk Scores

EPSS Score
3.85%
88.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSchromium-browser0, 37.0.2062.94-0ubuntu0.14.04.1~pkg1042, 37.0.2062.120-0ubuntu0.14.04.1~pkg1049
Ubuntu:18.04:LTSchromium-browser62.0.3202.94-0ubuntu1.1388, 62.0.3202.89-0ubuntu1.1386, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:14.04:LTSicu52.1-3ubuntu0.5, 52.1-3ubuntu0.6, 52.1-3ubuntu0.7
Ubuntu:16.04:LTSchromium-browser59.0.3071.109-0ubuntu0.16.04.1289, 0, 45.0.2454.101-0ubuntu1.1201
Ubuntu:16.04:LTSicu55.1-7ubuntu0.2, 55.1-7ubuntu0.3, 55.1-7ubuntu0.1
Ubuntu:16.04:LTSoxide-qt1.11.4-0ubuntu1, 1.11.5-0ubuntu1, 1.12.5-0ubuntu1

Timeline

References

Open in Interactive Console →