CVE detail
CVE-2025-5222
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Siemens SIDIS Secured SmartPlugCISA Alerts
l Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-
governmentwww.cisa.govJul 21, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-585531.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 27, 2025, 9:15 PM No excerpt available.
Vendor Advisorylists.debian.orgMay 27, 2025, 9:15 PM- https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957unicode-org.atlassian.net
No excerpt available.
referenceunicode-org.atlassian.netMay 27, 2025, 9:15 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2368600bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/security/cve/CVE-2025-5222access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/errata/RHSA-2025:12333access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/errata/RHSA-2025:12332access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/errata/RHSA-2025:12331access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/errata/RHSA-2025:12083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM - https://access.redhat.com/errata/RHSA-2025:11888access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2025, 9:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-45811CVSS 7.5 · High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fi…
- CVE-2026-63453CVSS 7.2 · High
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execut…
- CVE-2026-44880CVSS 8.8 · High
A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to ex…
- CVE-2026-16364CVSS 9.1 · Critical
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-44436CVSS 7.5 · High
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack t…
- CVE-2024-32389CVSS 3.5 · Low
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs comp…