Show filters
333 Total Results
Displaying 131-140 of 333
Sort by:
Attacker Value
Unknown
CVE-2016-1531
Disclosure Date: April 07, 2016 (last updated October 05, 2023)
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
0
Attacker Value
Unknown
CVE-2015-8607
Disclosure Date: January 13, 2016 (last updated October 05, 2023)
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
0
Attacker Value
Unknown
CVE-2015-5667
Disclosure Date: October 31, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.
0
Attacker Value
Unknown
CVE-2015-7686
Disclosure Date: October 06, 2015 (last updated October 05, 2023)
Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.
0
Attacker Value
Unknown
CVE-2013-7422
Disclosure Date: August 16, 2015 (last updated October 05, 2023)
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
0
Attacker Value
Unknown
CVE-2015-0898
Disclosure Date: March 21, 2015 (last updated October 05, 2023)
futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1592
Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-0871
Disclosure Date: February 07, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-8630
Disclosure Date: February 01, 2015 (last updated October 05, 2023)
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
0
Attacker Value
Unknown
CVE-2015-0868
Disclosure Date: February 01, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in Mrs. Shiromuku Perl CGI shiromuku(bu2)BBS before 2.91 allows remote attackers to execute arbitrary code by uploading an executable file.
0