Pcre

Pcre

33 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.14%
  • Published 16.02.2017 11:59:00
  • Last modified 20.04.2025 01:37:25

The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a craft...

Exploit
  • EPSS 0.71%
  • Published 13.12.2016 16:59:06
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection me...

Exploit
  • EPSS 2.89%
  • Published 13.12.2016 16:59:02
  • Last modified 12.04.2025 10:46:40

PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_]...

Exploit
  • EPSS 5.73%
  • Published 13.12.2016 16:59:00
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerabi...

  • EPSS 0.93%
  • Published 28.03.2016 16:59:00
  • Last modified 12.04.2025 10:46:40

pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as...

Exploit
  • EPSS 11.34%
  • Published 17.03.2016 23:59:01
  • Last modified 12.04.2025 10:46:40

The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arb...

Exploit
  • EPSS 4.43%
  • Published 03.01.2016 00:59:03
  • Last modified 12.04.2025 10:46:40

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgrou...

  • EPSS 7.68%
  • Published 02.12.2015 01:59:15
  • Last modified 12.04.2025 10:46:40

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as...

Exploit
  • EPSS 4.34%
  • Published 02.12.2015 01:59:01
  • Last modified 12.04.2025 10:46:40

PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular exp...

  • EPSS 2.09%
  • Published 16.12.2014 18:59:10
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.