296,746
Total vulnerabilities in the database
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
| Software | From | Fixed in | 
|---|---|---|
| pcre / perl_compatible_regular_expression_library | - | 8.37.x | 
| php / php | 5.6.0 | 5.6.18 | 
| php / php | 7.0.0 | 7.0.3 | 
| php / php | 5.5.0 | 5.5.32 |