Perl Compatible Regular Expression Library

Vendor:

First CVE: Nov 7, 2007 · Active for 18 years

17
Total CVEs
More Total CVEs than 94% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Perl Compatible Regular Expression Library over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2007
18 years ago
Most Recent CVE
Dec 2, 2015
3,891 days ago

CVE Severity & Scoring

Perl Compatible Regular Expression Library17 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (41.2%)
Unknown10 (58.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (41.2%)
High0 (0.0%)
Unknown10 (58.8%)
User Interaction
None7 (41.2%)
Unknown10 (58.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (41.2%)
Unknown10 (58.8%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have u
Dec 2, 20159.833NONO
PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspe
Dec 2, 20159.832NONO
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow
Dec 2, 20159.830NONO
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecifie
Dec 2, 20159.827NONO
PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibl
Dec 2, 20157.526NONO
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other imp
Dec 2, 20159.826NONO
The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ a
Dec 2, 20157.526NONO
PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denia
Dec 2, 20157.526NONO
The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer o
Dec 2, 20157.525NONO
The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involvi
Dec 2, 20156.423NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Perl Compatible Regular Expression Library

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.3616.44.1%00
7.116.42.5%00
7.016.42.5%00