Show filters
333 Total Results
Displaying 121-130 of 333
Sort by:
Attacker Value
Unknown
CVE-2016-9180
Disclosure Date: December 22, 2016 (last updated October 05, 2023)
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.
0
Attacker Value
Unknown
CVE-2016-1251
Disclosure Date: November 29, 2016 (last updated October 05, 2023)
There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.
0
Attacker Value
Unknown
CVE-2015-8978
Disclosure Date: November 22, 2016 (last updated October 05, 2023)
In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined as consisting of 10 of the previous entity, with the document consisting of a single instance of the largest entity, which expands to one billion copies of the first entity. The amount of computer memory used for handling an external SOAP call would likely exceed that available to the process parsing the XML.
0
Attacker Value
Unknown
CVE-2016-7489
Disclosure Date: November 10, 2016 (last updated October 05, 2023)
Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to elevated code execution.
0
Attacker Value
Unknown
CVE-2016-1246
Disclosure Date: October 05, 2016 (last updated October 05, 2023)
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
0
Attacker Value
Unknown
CVE-2016-4748
Disclosure Date: September 25, 2016 (last updated October 05, 2023)
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
0
Attacker Value
Unknown
CVE-2016-6185
Disclosure Date: August 02, 2016 (last updated November 08, 2023)
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
0
Attacker Value
Unknown
CVE-2016-1238
Disclosure Date: August 02, 2016 (last updated November 08, 2023)
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working direct…
0
Attacker Value
Unknown
CVE-2015-8853
Disclosure Date: May 25, 2016 (last updated October 05, 2023)
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."
0
Attacker Value
Unknown
CVE-2016-2381
Disclosure Date: April 08, 2016 (last updated October 05, 2023)
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
0