VDB
CVE-2005-2491
CVE-2005-2491
PUBLISHED
CVSS 7.5 HIGH
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.
EPSS 4.34% · 90.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.34%
90.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| pcre | pcre | 5.0, 6.1, 6.0 |
Timeline
- Aug 22, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 3, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- ADV-2005-2659 vdb
- FLSA:168516 vendor-advisory
- HPSBMA02159 vendor-advisory
- http://www.ethereal.com/appnotes/enpa-sa-00021.html url
- 16502 third-party-advisory
- SSRT051251 vendor-advisory
- 16679 third-party-advisory
- 604 third-party-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf url
- DSA-819 vendor-advisory
- ADV-2006-4320 vdb
- RHSA-2005:358 vendor-advisory
- oval:org.mitre.oval:def:1496 vdb
- 17252 third-party-advisory
- oval:org.mitre.oval:def:735 vdb
- [httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [5/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/ mailing-list
- [httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
…and 60 more