Show filters
333 Total Results
Displaying 111-120 of 333
Sort by:
Attacker Value
Unknown

CVE-2017-10672

Disclosure Date: June 29, 2017 (last updated October 05, 2023)
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
Attacker Value
Unknown

CVE-2017-4985

Disclosure Date: June 19, 2017 (last updated October 05, 2023)
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user may potentially escalate their privileges to root due to authorization checks not being performed on certain perl scripts. This may potentially be exploited by an attacker to run arbitrary commands as root on the targeted VNX Control Station system.
Attacker Value
Unknown

CVE-2015-8326

Disclosure Date: June 07, 2017 (last updated October 05, 2023)
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
Attacker Value
Unknown

CVE-2017-6512

Disclosure Date: June 01, 2017 (last updated October 05, 2023)
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
Attacker Value
Unknown

CVE-2017-0373

Disclosure Date: May 23, 2017 (last updated October 05, 2023)
The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.
Attacker Value
Unknown

CVE-2017-0374

Disclosure Date: May 23, 2017 (last updated October 05, 2023)
lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.
Attacker Value
Unknown

CVE-2017-6972

Disclosure Date: March 22, 2017 (last updated October 05, 2023)
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
Attacker Value
Unknown

CVE-2016-1249

Disclosure Date: February 17, 2017 (last updated October 05, 2023)
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
Attacker Value
Unknown

CVE-2015-8608

Disclosure Date: February 07, 2017 (last updated October 05, 2023)
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.
Attacker Value
Unknown

CVE-2016-9181

Disclosure Date: December 22, 2016 (last updated October 05, 2023)
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.