← Vulnerability feed

Vulnerability record · CVE-2018-18928 · published 4 November 2018

CVE-2018-18928: Icu-project international components for unicode integer overflow vulnerability

Icu Project · International Components For Unicode

International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.

9.8 CVSS 3.0 Critical EPSS 2.9% · top 13.5% CWE-190 · Integer overflow
9.8CVSS 3.0 base score, v2 7.5
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18928 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-5922Apple mac os x vulnerabilityUnspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has u…EPSS 3.0%9.8CVE-2017-17484Icu-project international components for unicode memory buffer overflow vulnerabilityThe ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls fo…EPSS 4.6%9.8CVE-2017-14952Icu-project international components for unicode double free vulnerabilityDouble free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary co…EPSS 5.1%9.8CVE-2014-9654Google chrome memory buffer overflow vulnerabilityThe Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.…EPSS 2.4%9.8CVE-2014-9911Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.…EPSS 5.5%9.8CVE-2016-7415Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remot…EPSS 5.8%9.8CVE-2016-6293Icu-project international components for unicode memory buffer overflow vulnerabilityThe uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that…EPSS 5.0%9.3CVE-2007-4771Icu-project international components for unicode vulnerabilityHeap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allow…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2018-18928), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.