Back
CVE-2015-3210
CRITICAL
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.
Published: Dec 13, 2016
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| pcre | pcre2 | 10.10 |
| pcre | pcre | 8.34 |
| pcre | pcre | 8.35 |
| pcre | pcre | 8.36 |
| pcre | pcre | 8.37 |
GitHub Security Advisory GHSA-rw29-r7x7-2gmq
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to...
References (12)
- http://rhn.redhat.com/errata/RHSA-2016-2750.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/01/7 Mailing List
- http://www.openwall.com/lists/oss-security/2015/12/02/11 Mailing List
- http://www.securityfocus.com/bid/74934 Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1132 Third Party Advisory
- https://bugs.exim.org/show_bug.cgi?id=1636 Exploit, Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/01/7 Mailing List
- http://www.openwall.com/lists/oss-security/2015/12/02/11 Mailing List
- http://www.securityfocus.com/bid/74934 Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1132 Third Party Advisory
- https://bugs.exim.org/show_bug.cgi?id=1636 Exploit, Issue Tracking, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
9.16%
Top 5% most likely to be exploited
Threat Score
41.9 / 100
Data Sources
NVD
EPSS
GitHub