NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28547  CVE-2015-8379  CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.    6.8  Medium  2017-01-19  2016-01-27  View
28548  CVE-2015-8380  The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a 1 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.    7.5  High  2017-01-19  2016-12-29  View
28549  CVE-2015-8381  The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?"R")(k"R")|((?"R")))H"Rk"Rf)|s(?"R"))))/ and /(?J:(?|(:(?|(?"R")(z(?|(?"R")(k"R")|((?"R")))k"R")|((?"R")))H"Ak"Rf)|s(?"R")))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.    7.5  High  2017-01-19  2016-12-29  View
28550  CVE-2015-8382  The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially initialized memory and application crash) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-2547.    6.4  Medium  2017-01-19  2016-12-27  View
28551  CVE-2015-8383  PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.    7.5  High  2017-01-19  2016-12-29  View

Page 15046 of 17672, showing 5 records out of 88360 total, starting on record 75226, ending on 75230

Actions