Lucene search

K
cve[email protected]CVE-2014-7926
HistoryJan 22, 2015 - 10:59 p.m.

CVE-2014-7926

2015-01-2222:59:07
CWE-17
web.nvd.nist.gov
55
cve-2014-7926
regular expressions
international components for unicode
icu
memory corruption
denial of service
google chrome

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.1%

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.

Affected configurations

NVD
Node
redhatenterprise_linux_desktop_supplementaryMatch6.0
OR
redhatenterprise_linux_server_supplementaryMatch6.0
OR
redhatenterprise_linux_server_supplementary_eusMatch6.6.z
OR
redhatenterprise_linux_workstation_supplementaryMatch6.0
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
googlechromeRange40.0.2214.85
Node
oraclecommunications_messaging_serverMatch7.0.5
OR
oraclecommunications_messaging_serverMatch8.0
Node
icu-projectinternational_components_for_unicodeRange<55.1c\/c\+\+
Node
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.5 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.1%