VYPR

Pcre

by Pcre

Source repositories

CVEs (64)

  • CVE-2015-3217HigDec 13, 2016
    risk 0.49cvss 7.5epss 0.06

    PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.

  • CVE-2015-8393HigDec 2, 2015
    risk 0.49cvss 7.5epss 0.04

    pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.

  • CVE-2014-9769HigMar 28, 2016
    risk 0.48cvss 7.3epss 0.03

    pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets…

  • CVE-2015-8387HigDec 2, 2015
    risk 0.48cvss 7.3epss 0.04

    PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp…

  • CVE-2026-86145HigSep 5, 2026
    risk 0.46cvss 8.2epss 0.00

    PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an…

  • CVE-2019-20454HigFeb 14, 2020
    risk 0.42cvss 7.5epss 0.02

    An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash…

  • CVE-2026-89161HigSep 11, 2026
    risk 0.41cvss 7.4epss 0.00

    In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

  • CVE-2015-2326MedJan 14, 2020
    risk 0.36cvss 5.5epss 0.02

    The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back…

  • CVE-2017-16231MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.01

    In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount…

  • CVE-2017-7244MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.03

    The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

  • CVE-2026-89158MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

  • CVE-2020-14155MedJun 15, 2020
    risk 0.35cvss 5.3epss 0.04

    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

  • CVE-2026-89157MedSep 11, 2026
    risk 0.30cvss 5.7epss 0.00

    PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

  • CVE-2026-89160LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

  • CVE-2026-89162LowSep 11, 2026
    risk 0.12cvss 2.9epss 0.00

    In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

  • CVE-2026-89156LowSep 11, 2026
    risk 0.12cvss 2.9epss 0.00

    PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

  • CVE-2015-8388Dec 2, 2015
    risk 0.01cvss —epss 0.07

    PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression,…

  • CVE-2014-8964Dec 16, 2014
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

  • CVE-2008-2371Jul 7, 2008
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains…

  • CVE-2025-58050CriAug 27, 2025
    risk 0.00cvss 9.1epss 0.01

    The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString)…