CVE-2015-3210: Pcre
Critical severity, CVSS 9.8. EPSS: 9.2% chance of exploitation in the next 30 days.
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.
Affected products
- Pcre Pcre: version 8.34 only; version 8.35 only; version 8.36 only; version 8.37 only
- Pcre PCRE2: version 10.10 only
Published 2016-12-13. Last modified 2026-06-17.