threat
engine
.sh
Back
·
··:··
Home
/
Product
/
pcre pcre2
Product
pcre pcre2
11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-58050
all versions
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-over
9.1
CRITICAL
CVE-2022-41409
< 10.41
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impact
7.5
HIGH
CVE-2022-1587
< 10.40
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit
9.1
CRITICAL
CVE-2022-1586
< 10.40
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2
9.1
CRITICAL
CVE-2019-20454
>= 10.31 and < 10.34
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted
7.5
HIGH
CVE-2017-8786
all versions
pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unsp
9.8
CRITICAL
CVE-2017-8399
< 10.30
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with
9.8
CRITICAL
CVE-2017-7186
all versions
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for
7.5
HIGH
CVE-2015-3217
all versions
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denia
7.5
HIGH
CVE-2015-3210
all versions
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a craft
9.8
CRITICAL
CVE-2016-3191
<= 10.21
The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles pattern
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin