Pcre

Perl Compatible Regular Expression Library

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.19%
  • Published 02.12.2015 01:59:08
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a ...

  • EPSS 3.8%
  • Published 02.12.2015 01:59:07
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript ...

Exploit
  • EPSS 1.77%
  • Published 02.12.2015 01:59:05
  • Last modified 12.04.2025 10:46:40

The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive inform...

Exploit
  • EPSS 9.05%
  • Published 02.12.2015 01:59:04
  • Last modified 12.04.2025 10:46:40

The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak...

Exploit
  • EPSS 1.24%
  • Published 02.12.2015 01:59:03
  • Last modified 12.04.2025 10:46:40

The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regul...

Exploit
  • EPSS 4.53%
  • Published 02.12.2015 01:59:00
  • Last modified 12.04.2025 10:46:40

PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other i...