Show filters
333 Total Results
Displaying 101-110 of 333
Sort by:
Attacker Value
Unknown
CVE-2014-5509
Disclosure Date: January 08, 2018 (last updated October 06, 2023)
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
0
Attacker Value
Unknown
CVE-2008-7319
Disclosure Date: November 07, 2017 (last updated October 05, 2023)
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.
0
Attacker Value
Unknown
CVE-2017-16248
Disclosure Date: November 01, 2017 (last updated October 05, 2023)
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.
0
Attacker Value
Unknown
CVE-2017-14867
Disclosure Date: September 29, 2017 (last updated November 08, 2023)
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
0
Attacker Value
Unknown
CVE-2017-12814
Disclosure Date: September 28, 2017 (last updated October 05, 2023)
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.
0
Attacker Value
Unknown
CVE-2017-12837
Disclosure Date: September 19, 2017 (last updated October 05, 2023)
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
0
Attacker Value
Unknown
CVE-2017-12883
Disclosure Date: September 19, 2017 (last updated October 05, 2023)
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
0
Attacker Value
Unknown
CVE-2010-3845
Disclosure Date: August 08, 2017 (last updated October 05, 2023)
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
0
Attacker Value
Unknown
CVE-2017-10789
Disclosure Date: July 01, 2017 (last updated October 05, 2023)
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
0
Attacker Value
Unknown
CVE-2017-10788
Disclosure Date: July 01, 2017 (last updated October 05, 2023)
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.
0