The ICU Project maintains the International Components for Unicode library, a foundational text-processing component embedded across a broad range of applications, browsers, and operating systems despite its narrow product footprint. Its vulnerabilities matter disproportionately because a single flaw in Unicode handling, normalization, or collation logic can propagate through every downstream product that links the library, making remediation a supply-chain coordination challenge rather than a localized patch. The vendor's disclosures have historically centered on parsing and data-handling edge cases inherent to comprehensive Unicode support across diverse character sets and locale-specific rules. Defenders should track this vendor's releases and prioritize downstream library updates across browser and operating-system vendors rather than treating ICU in isolation; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icu Project over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8147HIGH The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses a | May 25, 2015 | 7.5 | 42 | NO | YES |
CVE-2014-8146HIGH The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does n | May 25, 2015 | 7.5 | 42 | NO | YES |
CVE-2017-14952CRITICAL Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a | Oct 16, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-17484CRITICAL The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, wh | Dec 10, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-18928CRITICAL International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp. | Nov 4, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-7867HIGH International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in c | Apr 14, 2017 | 7.5 | 28 | NO | NO |
CVE-2017-7868HIGH International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in c | Apr 14, 2017 | 7.5 | 27 | NO | NO |
CVE-2015-5922HIGH Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vector | Oct 9, 2015 | 10.0 | 27 | NO | NO |
CVE-2014-9911CRITICAL Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attac | Jan 4, 2017 | 9.8 | 26 | NO | NO |
CVE-2016-7415CRITICAL Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial o | Sep 17, 2016 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icu Project.
Media articles that mention a CVE ID that affects a product developed by Icu Project — matched by CVE ID, not by vendor name.