Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-3217

PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2015-3217
  • Ibm » Powerkvm » Version: 2.1
    cpe:2.3:a:ibm:powerkvm:2.1
  • Ibm » Powerkvm » Version: 3.1
    cpe:2.3:a:ibm:powerkvm:3.1
  • Pcre » Pcre2 » Version: 10.10
    cpe:2.3:a:pcre:pcre2:10.10
  • Pcre » Pcre » Version: 7.8
    cpe:2.3:a:pcre:pcre:7.8
  • Pcre » Pcre » Version: 8.32
    cpe:2.3:a:pcre:pcre:8.32
  • Pcre » Pcre » Version: 8.33
    cpe:2.3:a:pcre:pcre:8.33
  • Pcre » Pcre » Version: 8.34
    cpe:2.3:a:pcre:pcre:8.34
  • Pcre » Pcre » Version: 8.35
    cpe:2.3:a:pcre:pcre:8.35
  • Pcre » Pcre » Version: 8.36
    cpe:2.3:a:pcre:pcre:8.36
  • Pcre » Pcre » Version: 8.37
    cpe:2.3:a:pcre:pcre:8.37


Contact Us

Shodan ® - All rights reserved