Show filters
333 Total Results
Displaying 111-120 of 333
Sort by:
Attacker Value
Unknown
CVE-2017-10672
Disclosure Date: June 29, 2017 (last updated October 05, 2023)
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
0
Attacker Value
Unknown
CVE-2017-4985
Disclosure Date: June 19, 2017 (last updated October 05, 2023)
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user may potentially escalate their privileges to root due to authorization checks not being performed on certain perl scripts. This may potentially be exploited by an attacker to run arbitrary commands as root on the targeted VNX Control Station system.
0
Attacker Value
Unknown
CVE-2015-8326
Disclosure Date: June 07, 2017 (last updated October 05, 2023)
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
0
Attacker Value
Unknown
CVE-2017-6512
Disclosure Date: June 01, 2017 (last updated October 05, 2023)
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
0
Attacker Value
Unknown
CVE-2017-0373
Disclosure Date: May 23, 2017 (last updated October 05, 2023)
The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.
0
Attacker Value
Unknown
CVE-2017-0374
Disclosure Date: May 23, 2017 (last updated October 05, 2023)
lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.
0
Attacker Value
Unknown
CVE-2017-6972
Disclosure Date: March 22, 2017 (last updated October 05, 2023)
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
0
Attacker Value
Unknown
CVE-2016-1249
Disclosure Date: February 17, 2017 (last updated October 05, 2023)
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
0
Attacker Value
Unknown
CVE-2015-8608
Disclosure Date: February 07, 2017 (last updated October 05, 2023)
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.
0
Attacker Value
Unknown
CVE-2016-9181
Disclosure Date: December 22, 2016 (last updated October 05, 2023)
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
0