Description
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Remediation
References
Related Vulnerabilities
Mailman Insufficiently Protected Credentials Vulnerability (CVE-2021-43332)
Apache HTTP Server Use After Free Vulnerability (CVE-2019-10082)
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.14)
WordPress Plugin PDF & Print by BestWebSoft Cross-Site Scripting (1.7.4)
WordPress Plugin Captcha by BestWebSoft Security Bypass (3.8.7)