International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Internationalcomponentsforunicode | — | Upgrade macOS to the latest version | Dec 16, 2011 | May 13, 2009 |
| Apple Safari | — | Upgrade to Apple Safari version 4.0Uninstall Apple Safari on Windows | Jan 5, 2012 | May 13, 2009 |
| Centos_linux | — | Upgrade libicuUpgrade libicu-docUpgrade libicu-develUpgrade icu | Dec 1, 2016 | May 13, 2009 |
| Debian | — | Upgrade icu | Jul 30, 2024 | May 13, 2009 |
| Oracle_linux | — | Upgrade libicu-develUpgrade icuUpgrade libicu-docUpgrade libicu | Oct 16, 2024 | Apr 17, 2007 |
| Suse | — | Upgrade icuUpgrade libicu-x86Upgrade libicu-32bitUpgrade libicuUpgrade libicu-develUpgrade libicu-docUpgrade libicu-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libicu38 | Nov 8, 2024 | May 13, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub