Show filters
333 Total Results
Displaying 131-140 of 333
Sort by:
Attacker Value
Unknown

CVE-2016-1531

Disclosure Date: April 07, 2016 (last updated October 05, 2023)
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
Attacker Value
Unknown

CVE-2015-8607

Disclosure Date: January 13, 2016 (last updated October 05, 2023)
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
Attacker Value
Unknown

CVE-2015-5667

Disclosure Date: October 31, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.
0
Attacker Value
Unknown

CVE-2015-7686

Disclosure Date: October 06, 2015 (last updated October 05, 2023)
Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.
0
Attacker Value
Unknown

CVE-2013-7422

Disclosure Date: August 16, 2015 (last updated October 05, 2023)
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
0
Attacker Value
Unknown

CVE-2015-0898

Disclosure Date: March 21, 2015 (last updated October 05, 2023)
futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1592

Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-0871

Disclosure Date: February 07, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-8630

Disclosure Date: February 01, 2015 (last updated October 05, 2023)
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
0
Attacker Value
Unknown

CVE-2015-0868

Disclosure Date: February 01, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in Mrs. Shiromuku Perl CGI shiromuku(bu2)BBS before 2.91 allows remote attackers to execute arbitrary code by uploading an executable file.
0