CVE-2017-6004
- EPSS 1.14%
- Veröffentlicht 16.02.2017 11:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a craft...
CVE-2015-5073
- EPSS 0.71%
- Veröffentlicht 13.12.2016 16:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection me...
CVE-2015-3217
- EPSS 2.89%
- Veröffentlicht 13.12.2016 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_]...
CVE-2015-3210
- EPSS 5.73%
- Veröffentlicht 13.12.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerabi...
CVE-2014-9769
- EPSS 0.93%
- Veröffentlicht 28.03.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as...
CVE-2016-3191
- EPSS 11.34%
- Veröffentlicht 17.03.2016 23:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arb...
CVE-2016-1283
- EPSS 4.43%
- Veröffentlicht 03.01.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgrou...
CVE-2015-8391
- EPSS 7.68%
- Veröffentlicht 02.12.2015 01:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as...
CVE-2015-2328
- EPSS 4.34%
- Veröffentlicht 02.12.2015 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular exp...
- EPSS 2.09%
- Veröffentlicht 16.12.2014 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.