cbcvebase.

Debian Pcre3 vulnerabilities

47 known vulnerabilities affecting debian/pcre3.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH12MEDIUM11LOW15

Vulnerabilities

Page 1 of 3
CVE-2016-3191P3CRITICALCVSS 9.8fixed in pcre2 10.21-1 (bookworm)2016
CVE-2016-3191 [CRITICAL] CVE-2016-3191: pcre2 - The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_... The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrat
debian
CVE-2015-3210P3CRITICALCVSS 9.8fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-3210 [CRITICAL] CVE-2015-3210: pcre3 - Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remo... Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?Pc)(?Pa(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384. Scope: local bookworm: resolved (fixed in 2:8.35-7.2) bullseye: resolved (fixed in 2:8.35-7.2)
debian
CVE-2015-5073P3CRITICALCVSS 9.1fixed in pcre3 2:8.35-7 (bookworm)2015
CVE-2015-5073 [CRITICAL] CVE-2015-5073: pcre3 - Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in... Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis. Scope: local bookworm: resolved (fixed in
debian
CVE-2016-1283P3LOWCVSS 9.8fixed in pcre3 2:8.38-3.1 (bookworm)2016
CVE-2016-1283 [CRITICAL] CVE-2016-1283: pcre2 - The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?... The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecifi
debian
CVE-2015-8386P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8386 [CRITICAL] CVE-2015-8386: pcre3 - PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutuall... PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed
debian
CVE-2015-3217P3HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-3217 [HIGH] CVE-2015-3217: pcre3 - PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, w... PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: resolved (fixed in 2:8.38-1)
debian
CVE-2008-0674P3MEDIUMCVSS 7.5fixed in pcre3 7.6-1 (bookworm)2008
CVE-2008-0674 [HIGH] CVE-2008-0674: pcre3 - Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary ... Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class with a large number of characters with Unicode code points greater than 255. Scope: local bookworm: resolved (fixed in 7.6-1) bullseye: resolved (fixed in 7.6-1)
debian
CVE-2015-8383P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8383 [CRITICAL] CVE-2015-8383: pcre3 - PCRE before 8.38 mishandles certain repeated conditional groups, which allows re... PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: resolved (fixed
debian
CVE-2015-8394P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8394 [CRITICAL] CVE-2015-8394: pcre3 - PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which... PCRE before 8.38 mishandles the (?() and (?(R) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: resolved (fixed in 2:
debian
CVE-2015-8393P3HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8393 [HIGH] CVE-2015-8393: pcre3 - pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which mi... pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: resolved (fixed in 2:8.38-1)
debian
CVE-2015-8391P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8391 [CRITICAL] CVE-2015-8391: pcre3 - The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certa... The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38
debian
CVE-2015-8381P3HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8381 [HIGH] CVE-2015-8381: pcre3 - The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compi... The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a den
debian
CVE-2008-2371P3MEDIUMCVSS 7.5fixed in pcre3 7.6-2.1 (bookworm)2008
CVE-2008-2371 [HIGH] CVE-2008-2371: pcre3 - Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expr... Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches. Scope: local bookworm: resolved (fixed in 7.6-2.1) bullseye: resolved (fixe
debian
CVE-2015-8388P3HIGHCVSS 7.5fixed in pcre3 2:8.35-7 (bookworm)2015
CVE-2015-8388 [HIGH] CVE-2015-8388: pcre3 - PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related p... PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookwor
debian
CVE-2015-8380P3LOWCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8380 [HIGH] CVE-2015-8380: pcre2 - The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // patter... The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved bul
debian
CVE-2015-8390P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8390 [CRITICAL] CVE-2015-8390: pcre3 - PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which... PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullse
debian
CVE-2015-8389P3CRITICALCVSS 9.8fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8389 [CRITICAL] CVE-2015-8389: pcre3 - PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, wh... PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye:
debian
CVE-2015-8385P3HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8385 [HIGH] CVE-2015-8385: pcre3 - PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patte... PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolve
debian
CVE-2015-8387P3HIGHCVSS 7.3fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8387 [HIGH] CVE-2015-8387: pcre3 - PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls... PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: re
debian
CVE-2014-9769P3HIGHCVSS 7.3fixed in pcre3 2:8.38-1 (bookworm)2014
CVE-2014-9769 [HIGH] CVE-2014-9769: pcre3 - pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize ne... pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a regular expression in an Emerging Threats Open ruleset. S
debian
Debian Pcre3 vulnerabilities | cvebase