Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Icu Project

First CVE: Jan 29, 2008Active for: 18 yearsTotal CVEs: 42

The ICU Project maintains the International Components for Unicode library, a foundational text-processing component embedded across a broad range of applications, browsers, and operating systems despite its narrow product footprint. Its vulnerabilities matter disproportionately because a single flaw in Unicode handling, normalization, or collation logic can propagate through every downstream product that links the library, making remediation a supply-chain coordination challenge rather than a localized patch. The vendor's disclosures have historically centered on parsing and data-handling edge cases inherent to comprehensive Unicode support across diverse character sets and locale-specific rules. Defenders should track this vendor's releases and prioritize downstream library updates across browser and operating-system vendors rather than treating ICU in isolation; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Icu Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2008
18 years ago
Most Recent CVE
Mar 12, 2020
2,325 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-8147HIGH
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses a
May 25, 20157.542NOYES
CVE-2014-8146HIGH
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does n
May 25, 20157.542NOYES
CVE-2017-14952CRITICAL
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a
Oct 16, 20179.833NONO
CVE-2017-17484CRITICAL
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, wh
Dec 10, 20179.831NONO
CVE-2018-18928CRITICAL
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.
Nov 4, 20189.830NONO
CVE-2017-7867HIGH
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in c
Apr 14, 20177.528NONO
CVE-2017-7868HIGH
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in c
Apr 14, 20177.527NONO
CVE-2015-5922HIGH
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vector
Oct 9, 201510.027NONO
CVE-2014-9911CRITICAL
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attac
Jan 4, 20179.826NONO
CVE-2016-7415CRITICAL
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial o
Sep 17, 20169.826NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
14%
52%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (57.1%)
Unknown9 (42.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (57.1%)
High0 (0.0%)
Unknown9 (42.9%)
User Interaction
None9 (42.9%)
Unknown9 (42.9%)
Required3 (14.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (57.1%)
Unknown9 (42.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Icu Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Icu Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Icu Project's Products

View all 4 CNAs →

Top CWEs