Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2007-4767

Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence, (2) a \P sequence, or (3) a \P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code.

  • Published: Nov 8, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-4767
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
pcre / pcre - 6.1.x
pcre / pcre - 7.3.x
pcre / pcre - 6.0.x