cbcvebase.

Debian Pcre3 vulnerabilities

47 known vulnerabilities affecting debian/pcre3.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH12MEDIUM11LOW15

Vulnerabilities

Page 2 of 3
CVE-2015-2328P3LOWCVSS 7.5fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-2328 [HIGH] CVE-2015-2328: pcre3 - PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns w... PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local bookworm: resolved (fixed in
debian
CVE-2017-7186P3HIGHCVSS 7.5fixed in pcre2 10.22-3 (bookworm)2017
CVE-2017-7186 [HIGH] CVE-2017-7186: pcre2 - libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to caus... libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup. Scope: local bookworm: resolved (fixed in 10.22-3) bullseye: resolved (fixed in 10.22-3) forky: resolved (fixed in 10.22-3) sid: resolved (fixed in 10.22-3)
debian
CVE-2005-2491P3LOWCVSS 7.5fixed in gnumeric 1.5.1-1 (bookworm)2005
CVE-2005-2491 [HIGH] CVE-2005-2491: gnumeric - Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE)... Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.5.1-1) bullseye: resolved (fixed i
debian
CVE-2015-8392P3HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8392 [HIGH] CVE-2015-8392: pcre3 - PCRE before 8.38 mishandles certain instances of the (?| substring, which allows... PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8395. Sc
debian
CVE-2015-8384P3HIGHCVSS 7.5fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-8384 [HIGH] CVE-2015-8384: pcre3 - PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patt... PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE
debian
CVE-2017-6004P4HIGHCVSS 7.5fixed in pcre3 2:8.39-2.1 (bookworm)2017
CVE-2017-6004 [HIGH] CVE-2017-6004: pcre3 - The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through ... The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression. Scope: local bookworm: resolved (fixed in 2:8.39-2.1) bullseye: resolved (fixed in 2:8.39-2.1)
debian
CVE-2015-2327P4LOWCVSS 7.5fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-2327 [HIGH] CVE-2015-2327: pcre3 - PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patt... PCRE before 8.36 mishandles the /(((a\2)|(a*)\g))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. Scope: local b
debian
CVE-2007-4768P3LOWCVSS 6.8fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-4768 [MEDIUM] CVE-2007-4768: glib2.0 - Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library ... Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized. Scope: local bookworm: resolved (fixed in 2.14.3-1) bullseye: resolved (fixed in 2.14.3-1) forky: resolved (fi
debian
CVE-2015-2325P4LOWCVSS 7.8fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-2325 [HIGH] CVE-2015-2325: pcre3 - The compile_branch function in PCRE before 8.37 allows context-dependent attacke... The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum q
debian
CVE-2015-8395P4HIGHCVSS 7.5fixed in pcre3 2:8.38-1 (bookworm)2015
CVE-2015-8395 [HIGH] CVE-2015-8395: pcre3 - PCRE before 8.38 mishandles certain references, which allows remote attackers to... PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392. Scope: local bookworm: resolved (fixed in 2:8.38-1) bullseye: res
debian
CVE-2007-4766P4LOWCVSS 7.5fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-4766 [HIGH] CVE-2007-4766: glib2.0 - Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library ... Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 7.3 allow context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via unspecified escape (backslash) sequences. Scope: local bookworm: resolved (fixed in 2.14.3-1) bullseye: resolved (fixed in 2.14.3-1) forky: resolved (fixed in 2.14.3-1) sid: reso
debian
CVE-2014-8964P4MEDIUMCVSS 5.0fixed in pcre3 2:8.35-3.3 (bookworm)2014
CVE-2014-8964 [MEDIUM] CVE-2014-8964: pcre3 - Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to c... Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats. Scope: local bookworm: resolved (fixed in 2:8.35-3.3) bullseye: resolved (fixed in 2:8.35-3.3)
debian
CVE-2006-7228P4MEDIUMCVSS 4.3fixed in pcre3 6.2-1 (bookworm)2006
CVE-2006-7228 [MEDIUM] CVE-2006-7228: pcre3 - Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7... Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 might allow context-dependent attackers to execute arbitrary code via a regular expression that involves large (1) min, (2) max, or (3) duplength values that cause an incorrect length calculation and trigger a buffer overflow, a different vulnerability than CVE-2006-7227. NOTE: this issue
debian
CVE-2006-7227P4MEDIUMCVSS 4.3fixed in pcre3 6.2-1 (bookworm)2006
CVE-2006-7227 [MEDIUM] CVE-2006-7227: pcre3 - Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7... Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to execute arbitrary code via a regular expression containing a large number of named subpatterns (name_count) or long subpattern names (max_name_size), which triggers a buffer overflow. NOTE: this issue was originally subsumed by CVE-2006-7224, but that
debian
CVE-2007-1660P4LOWCVSS 6.8fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-1660 [MEDIUM] CVE-2007-1660: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly c... Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified "multiple forms of character class", which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2.14.3-1) bullseye: resolved (f
debian
CVE-2020-14155P4MEDIUMCVSS 5.3fixed in pcre3 2:8.39-13 (bookworm)2020
CVE-2020-14155 [MEDIUM] CVE-2020-14155: pcre3 - libpcre in PCRE before 8.44 allows an integer overflow via a large number after ... libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. Scope: local bookworm: resolved (fixed in 2:8.39-13) bullseye: resolved (fixed in 2:8.39-13)
debian
CVE-2007-1659P4LOWCVSS 6.8fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-1659 [MEDIUM] CVE-2007-1659: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-depe... Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes. Scope: local bookworm: resolved (fixed in 2.14.3-1) bullseye: resolved (fixed in 2.14.3-1) forky: resolved (fixed in 2
debian
CVE-2015-8382P4MEDIUMCVSS 6.4fixed in pcre3 2:8.35-7.2 (bookworm)2015
CVE-2015-8382 [MEDIUM] CVE-2015-8382: pcre3 - The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd)... The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially initialized memory and application crash) via a crafte
debian
CVE-2007-4767P4LOWCVSS 5.0fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-4767 [MEDIUM] CVE-2007-4767: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly c... Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence, (2) a \P sequence, or (3) a \P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code. Scope: local bookworm: resolved (fixed in 2.14.3-1) bullseye: resolved (fixed in 2
debian
CVE-2007-1661P4LOWCVSS 6.4fixed in glib2.0 2.14.3-1 (bookworm)2007
CVE-2007-1661 [MEDIUM] CVE-2007-1661: glib2.0 - Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far ... Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns. Scope: local bookworm: resolved (fixed i
debian
Debian Pcre3 vulnerabilities | cvebase