Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-4771

25
FAUCET Score

CVE-2007-4771 describes a heap-based buffer overflow in the doInterval function of libicu in International Components for Unicode (ICU) versions 3.8.1 and earlier. This vulnerability allows attackers to cause a denial of service through excessive memory consumption and potentially other unspecified impacts via specially crafted regular expressions. With a CVSS score of 9.3, it is considered critical due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.8.1CPE matchmatch criteria
cpe:2.3:a:icu-project:international_components_for_unicode:*:*:*:*:*:c\/c\+\+:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.54%
Probability of exploitation in next 30 days
EPSS Percentile
83.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0254 is in the 40th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

denopatch availablevia llm_extracted
Fixed in: 2.4
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 2.4
View patch
nessuspatch availablevia llm_extracted
Fixed in: 2.4
postgresqlpatch availablevia llm_extracted
Fixed in: 2.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: icu-0:3.6-5.11.1
View patch

Vendor Advisories (5)

redhatCVE-2007-4771Important

libicu incomplete interval handling

Jan 22, 2008
denollm-deno-436007f2660397b3

Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution

postgresqlllm-postgresql-742ff41799cab9ca

Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution

libreofficellm-libreoffice-cb3d5d9810d94cb4

Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution

nessusllm-nessus-82537adb6987cd4e

Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution

References

lists.opensuse.org / opensuse-security-announce/2008-03/msg00001.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2008-0090.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/28575
Permissions Required
secunia.com / advisories/28615
Permissions Required
secunia.com / advisories/28669
Permissions Required
secunia.com / advisories/28783
Permissions Required
secunia.com / advisories/29194
Permissions Required
secunia.com / advisories/29242
Permissions Required
secunia.com / advisories/29291
Permissions Required
secunia.com / advisories/29294
Permissions Required
secunia.com / advisories/29333
Permissions Required
secunia.com / advisories/29852
Permissions Required
secunia.com / advisories/29910
Permissions Required
secunia.com / advisories/29987
Permissions Required
secunia.com / advisories/30179
Permissions Required
security.gentoo.org / glsa/glsa-200803-20.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200805-16.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/39936
Third Party AdvisoryVDB Entry
issues.rpath.com / browse/RPL-2199
Third Party Advisory
sourceforge.net / mailarchive/message.php
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10507
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5431
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
redhat.com / archives/fedora-package-announce/2008-January/msg00896.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-January/msg00921.html
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2008-0043
Third Party Advisory
debian.org / security/2008/dsa-1511
Third Party Advisory
mandriva.com / security/advisories
Broken Link
novell.com / linux/security/advisories/2008_23_openoffice.html
Third Party Advisory
openoffice.org / security/cves/CVE-2007-4770.html
Third Party Advisory
openoffice.org / security/cves/CVE-2007-5745.html
Third Party Advisory
securityfocus.com / archive/1/487677/100/0/threaded
securityfocus.com / bid/27455
PatchThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-591-1
Third Party Advisory
vupen.com / english/advisories/2008/0282
Third Party Advisory
vupen.com / english/advisories/2008/0807/references
Third Party Advisory
vupen.com / english/advisories/2008/1375/references
Third Party Advisory