Search CVE reports


Toggle filters

141 – 150 of 251 results


CVE-2014-9906

Medium priority

Some fixes available 2 of 3

Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.

1 affected package

libdbd-mysql-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdbd-mysql-perl
Show less packages

CVE-2016-6185

Low priority

Some fixes available 2 of 4

The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2016-1238

Medium priority

Some fixes available 2 of 7

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8)...

2 affected packages

libsys-syslog-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsys-syslog-perl Not in release
perl Not affected
Show less packages

CVE-2015-8853

Low priority

Some fixes available 1 of 3

The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2016-2381

Medium priority
Fixed

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2015-8607

Medium priority
Fixed

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection...

2 affected packages

libfile-spec-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfile-spec-perl
perl
Show less packages

CVE-2015-5667

Medium priority

Some fixes available 1 of 4

Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.

1 affected package

libhtml-scrubber-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhtml-scrubber-perl Not affected
Show less packages

CVE-2015-7686

Low priority
Vulnerable

Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail...

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-perl Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2013-7422

Low priority

Some fixes available 2 of 3

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2015-3451

Medium priority
Fixed

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

1 affected package

libxml-libxml-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml-libxml-perl
Show less packages