Show filters
333 Total Results
Displaying 141-150 of 333
Sort by:
Attacker Value
Unknown
CVE-2014-9130
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
0
Attacker Value
Unknown
CVE-2014-7180
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.
0
Attacker Value
Unknown
CVE-2012-5697
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.
0
Attacker Value
Unknown
CVE-2013-7329
Disclosure Date: October 06, 2014 (last updated October 05, 2023)
The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the dump_html function.
0
Attacker Value
Unknown
CVE-2014-1875
Disclosure Date: October 06, 2014 (last updated October 05, 2023)
The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.
0
Attacker Value
Unknown
CVE-2014-4330
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
0
Attacker Value
Unknown
CVE-2014-4720
Disclosure Date: July 06, 2014 (last updated October 05, 2023)
Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase," a different vulnerability than CVE-2014-0477.
0
Attacker Value
Unknown
CVE-2014-0477
Disclosure Date: July 03, 2014 (last updated October 05, 2023)
The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC 2822 address.
0
Attacker Value
Unknown
CVE-2012-6141
Disclosure Date: June 04, 2014 (last updated October 05, 2023)
The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.
0
Attacker Value
Unknown
CVE-2012-6142
Disclosure Date: June 04, 2014 (last updated October 05, 2023)
Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
0