PCRE kayıtları
pcre üreticisine ait 64 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %98,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer30
- CWE-125 Out-of-bounds Read10
- CWE-190 Integer Overflow or Wraparound6
- CWE-189 Numeric Errors4
- CWE-787 Out-of-bounds Write2
- CWE-590 Free of Memory not on the Heap1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
64 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2015-3210İstismar yok | Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regularpcre · pcre2 · CWE-787 | Kritik9,8 | — | %9,2 | 13 Ara 2016 |
42Planlayın | CVE-2016-3191İstismar yok | The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containipcre · pcre · CWE-119 | Kritik9,8 | — | %8,4 | 17 Mar 2016 |
41Planlayın | CVE-2016-1283İstismar yok | The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?Jpcre · pcre · CWE-119 | Kritik9,8 | — | %7,8 | 2 Oca 2016 |
41Planlayın | CVE-2015-8386İstismar yok | PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to capcre · perl compatible regular expression library · CWE-119 | Kritik9,8 | — | %6,9 | 1 Ara 2015 |
41Planlayın | CVE-2015-8391İstismar yok | The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denipcre · pcre · CWE-119 | Kritik9,8 | — | %6,4 | 1 Ara 2015 |
41Planlayın | CVE-2015-8383İstismar yok | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflowpcre · perl compatible regular expression library · CWE-119 | Kritik9,8 | — | %6,1 | 1 Ara 2015 |
40Planlayın | CVE-2015-8394İstismar yok | PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integpcre · perl compatible regular expression library · CWE-190 | Kritik9,8 | — | %4,8 | 1 Ara 2015 |
40Planlayın | CVE-2015-8390İstismar yok | PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninipcre · perl compatible regular expression library · CWE-908 | Kritik9,8 | — | %4,7 | 1 Ara 2015 |
40Planlayın | CVE-2017-8786İstismar yok | pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified otpcre · pcre2 · CWE-119 | Kritik9,8 | — | %4,1 | 4 May 2017 |
40Planlayın | CVE-2015-8389İstismar yok | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (inpcre · perl compatible regular expression library · CWE-119 | Kritik9,8 | — | %3,9 | 1 Ara 2015 |
40Planlayın | CVE-2017-8399İstismar yok | PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very manypcre · pcre2 · CWE-119 | Kritik9,8 | — | %3,1 | 1 May 2017 |
38İzleyin | CVE-2015-5073İstismar yok | Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial pcre · pcre · CWE-119 | Kritik9,1 | — | %7,7 | 13 Ara 2016 |
37İzleyin | CVE-2022-1586İstismar yok | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compipcre · pcre2 · CWE-125 | Kritik9,1 | — | %3,4 | 16 May 2022 |
37İzleyin | CVE-2022-1587İstismar yok | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.cpcre · pcre2 · CWE-125 | Kritik9,1 | — | %2,8 | 16 May 2022 |
32İzleyin | CVE-2008-2371İstismar yok | Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackerspcre · pcre · CWE-787 | Yüksek7,5 | — | %6,7 | 7 Tem 2008 |
32İzleyin | CVE-2015-8388İstismar yok | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows pcre · perl compatible regular expression library · CWE-119 | Yüksek7,5 | — | %6,6 | 1 Ara 2015 |
32İzleyin | CVE-2015-3217İstismar yok | PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of servipcre · pcre2 · CWE-119 | Yüksek7,5 | — | %6,2 | 13 Ara 2016 |
32İzleyin | CVE-2008-0674İstismar yok | Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class wpcre · pcre · CWE-119 | Yüksek7,5 | — | %5,9 | 18 Şub 2008 |
32İzleyin | CVE-2015-8385İstismar yok | PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attpcre · perl compatible regular expression library · CWE-119 | Yüksek7,5 | — | %5,6 | 1 Ara 2015 |
32İzleyin | CVE-2015-8381İstismar yok | The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R'pcre · perl compatible regular expression library · CWE-119 | Yüksek7,5 | — | %5,3 | 1 Ara 2015 |
32İzleyin | CVE-2015-2328İstismar yok | PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to causpcre · pcre · CWE-19 | Yüksek7,5 | — | %5,2 | 1 Ara 2015 |
32İzleyin | CVE-2017-7186İstismar yok | libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read accespcre · pcre · CWE-119 | Yüksek7,5 | — | %5,0 | 19 Mar 2017 |
32İzleyin | CVE-2017-7246İstismar yok | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a pcre · pcre · CWE-119 | Yüksek7,8 | — | %2,6 | 23 Mar 2017 |
32İzleyin | CVE-2017-7245İstismar yok | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a pcre · pcre · CWE-119 | Yüksek7,8 | — | %2,4 | 23 Mar 2017 |
31İzleyin | CVE-2017-6004İstismar yok | The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled versiopcre · pcre · CWE-125 | Yüksek7,5 | — | %4,5 | 16 Şub 2017 |
- CVE-2015-321042Planlayın
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular
KritikCVSS 9,8İstismar yokEPSS %9pcre · pcre213 Ara 2016
- CVE-2016-319142Planlayın
The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containi
KritikCVSS 9,8İstismar yokEPSS %8pcre · pcre17 Mar 2016
- CVE-2016-128341Planlayın
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J
KritikCVSS 9,8İstismar yokEPSS %8pcre · pcre2 Oca 2016
- CVE-2015-838641Planlayın
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to ca
KritikCVSS 9,8İstismar yokEPSS %7pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-839141Planlayın
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a deni
KritikCVSS 9,8İstismar yokEPSS %6pcre · pcre1 Ara 2015
- CVE-2015-838341Planlayın
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow
KritikCVSS 9,8İstismar yokEPSS %6pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-839440Planlayın
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integ
KritikCVSS 9,8İstismar yokEPSS %5pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-839040Planlayın
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (unini
KritikCVSS 9,8İstismar yokEPSS %5pcre · perl compatible regular expression library1 Ara 2015
- CVE-2017-878640Planlayın
pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified ot
KritikCVSS 9,8İstismar yokEPSS %4pcre · pcre24 May 2017
- CVE-2015-838940Planlayın
PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (in
KritikCVSS 9,8İstismar yokEPSS %4pcre · perl compatible regular expression library1 Ara 2015
- CVE-2017-839940Planlayın
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many
KritikCVSS 9,8İstismar yokEPSS %3pcre · pcre21 May 2017
- CVE-2015-507338İzleyin
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial
KritikCVSS 9,1İstismar yokEPSS %8pcre · pcre13 Ara 2016
- CVE-2022-158637İzleyin
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compi
KritikCVSS 9,1İstismar yokEPSS %3pcre · pcre216 May 2022
- CVE-2022-158737İzleyin
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c
KritikCVSS 9,1İstismar yokEPSS %3pcre · pcre216 May 2022
- CVE-2008-237132İzleyin
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers
YüksekCVSS 7,5İstismar yokEPSS %7pcre · pcre7 Tem 2008
- CVE-2015-838832İzleyin
PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows
YüksekCVSS 7,5İstismar yokEPSS %7pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-321732İzleyin
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of servi
YüksekCVSS 7,5İstismar yokEPSS %6pcre · pcre213 Ara 2016
- CVE-2008-067432İzleyin
Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class w
YüksekCVSS 7,5İstismar yokEPSS %6pcre · pcre18 Şub 2008
- CVE-2015-838532İzleyin
PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote att
YüksekCVSS 7,5İstismar yokEPSS %6pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-838132İzleyin
The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R'
YüksekCVSS 7,5İstismar yokEPSS %5pcre · perl compatible regular expression library1 Ara 2015
- CVE-2015-232832İzleyin
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to caus
YüksekCVSS 7,5İstismar yokEPSS %5pcre · pcre1 Ara 2015
- CVE-2017-718632İzleyin
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read acces
YüksekCVSS 7,5İstismar yokEPSS %5pcre · pcre19 Mar 2017
- CVE-2017-724632İzleyin
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a
YüksekCVSS 7,8İstismar yokEPSS %3pcre · pcre23 Mar 2017
- CVE-2017-724532İzleyin
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a
YüksekCVSS 7,8İstismar yokEPSS %2pcre · pcre23 Mar 2017
- CVE-2017-600431İzleyin
The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled versio
YüksekCVSS 7,5İstismar yokEPSS %5pcre · pcre16 Şub 2017