Search CVE reports
1 – 10 of 36 results
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within...
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | — | Not affected | Not affected | Not affected | Not affected |
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Not affected | Not affected | Vulnerable | Vulnerable | Vulnerable |
Some fixes available 3 of 5
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused...
1 affected package
pcre2
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pcre2 | Not affected | Not affected | Fixed | Fixed | Fixed |