CVE-2014-8964 describes a heap-based buffer overflow in PCRE versions 8.36 and earlier, impacting products like MariaDB, Oracle, and Red Hat. This vulnerability, with a CVSS score of 5.0, allows remote attackers to cause a denial of service or other unspecified impact through a crafted regular expression, requiring low attack complexity and no authentication. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, despite some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.36CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.18CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
19CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* | ||
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.