CVE-2020-14155Medium· 5.3▾ Sunlitlibpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.2%
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
pcre < 8.44macos < 11.0.1gitlab < 12.10.13gitlab >= 13.0.0, < 13.0.8gitlab >= 13.1.0, < 13.1.2communications_cloud_native_core_policy = 1.15.0active_iq_unified_managercloud_backupclustered_data_ontapontap_select_deploy_administration_utilitysteelstore_cloud_integrated_storageh410c_firmwareh300s_firmwareh500s_firmwareh700s_firmwareh410s_firmwareuniversal_forwarder >= 8.2.0, < 8.2.12universal_forwarder >= 9.0.0, < 9.0.6universal_forwarder = 9.1.0Upgrade past the affected range:
pcre 8.44macos 11.0.1gitlab 13.1.2universal_forwarder 9.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2019-20838High· 7.5libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
CVE-2021-3520Critical· 9.8There's a flaw in lz4
CVE-2026-89158Medium· 6.5PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
CVE-2026-89157Medium· 5.7PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
CVE-2022-2285High· 7.8Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
CVE-2026-2921High· 7.8GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability