Search CVE reports
11 – 20 of 53 results
CVE-2015-3217
Medium priorityPCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by...
1 affected packages
pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre3 | — | — | — | — | — |
CVE-2014-9769
Medium prioritypcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via...
1 affected packages
pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre3 | — | — | — | — | Not affected |
CVE-2016-3191
Medium prioritySome fixes available 2 of 5
The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | Not affected | Not affected |
pcre3 | — | — | — | Not affected | Not affected |
CVE-2016-1283
Medium prioritySome fixes available 1 of 5
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | Not affected | Not affected |
pcre3 | — | — | — | Not affected | Not affected |
CVE-2015-8395
Low prioritySome fixes available 1 of 2
PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |
CVE-2015-8394
Low prioritySome fixes available 3 of 4
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression,...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |
CVE-2015-8393
Low prioritySome fixes available 3 of 4
pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |
CVE-2015-8392
Low prioritySome fixes available 1 of 2
PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |
CVE-2015-8391
Low prioritySome fixes available 2 of 3
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |
CVE-2015-8390
Low prioritySome fixes available 3 of 4
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular...
2 affected packages
pcre2, pcre3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pcre2 | — | — | — | — | Not affected |
pcre3 | — | — | — | — | Not affected |