Show filters
333 Total Results
Displaying 171-180 of 333
Sort by:
Attacker Value
Unknown

CVE-2012-2981

Disclosure Date: September 11, 2012 (last updated October 05, 2023)
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
0
Attacker Value
Unknown

CVE-2012-1151

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.
0
Attacker Value
Unknown

CVE-2012-1152

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.
0
Attacker Value
Unknown

CVE-2012-2451

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.
0
Attacker Value
Unknown

CVE-2012-0453

Disclosure Date: February 25, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
0
Attacker Value
Unknown

CVE-2011-5060

Disclosure Date: January 13, 2012 (last updated October 04, 2023)
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
0
Attacker Value
Unknown

CVE-2011-4114

Disclosure Date: January 13, 2012 (last updated November 08, 2023)
The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.
0
Attacker Value
Unknown

CVE-2011-2939

Disclosure Date: January 13, 2012 (last updated October 04, 2023)
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2011-3597

Disclosure Date: January 13, 2012 (last updated October 04, 2023)
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.
0
Attacker Value
Unknown

CVE-2011-4616

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.
0