Total vulnerabilities in the database
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.
Software | From | Fixed in |
---|---|---|
pcre / pcre2 | 10.10 | 10.10.x |
pcre / pcre | 8.34 | 8.34.x |
pcre / pcre | 8.36 | 8.36.x |
pcre / pcre | 8.37 | 8.37.x |
pcre / pcre | 8.35 | 8.35.x |