Show filters
141 Total Results
Displaying 21-30 of 141
Sort by:
Attacker Value
Unknown
CVE-2020-10543
Disclosure Date: June 05, 2020 (last updated February 21, 2025)
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
0
Attacker Value
Unknown
CVE-2020-10674
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.
0
Attacker Value
Unknown
CVE-2010-3438
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
0
Attacker Value
Unknown
CVE-2019-1010161
Disclosure Date: July 25, 2019 (last updated November 27, 2024)
perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(crafting user-controlled input to bypass authentication). The fixed version is: 0.023.
0
Attacker Value
Unknown
CVE-2019-1010263
Disclosure Date: July 17, 2019 (last updated November 27, 2024)
Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: network connectivity. The fixed version is: after commit b98a59b42ded9f9e51b2560410106207c2152d6c.
0
Attacker Value
Unknown
CVE-2018-18313
Disclosure Date: December 07, 2018 (last updated November 08, 2023)
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
0
Attacker Value
Unknown
CVE-2018-18311
Disclosure Date: December 07, 2018 (last updated November 08, 2023)
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
0
Attacker Value
Unknown
CVE-2018-18314
Disclosure Date: December 07, 2018 (last updated November 08, 2023)
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
0
Attacker Value
Unknown
CVE-2018-18312
Disclosure Date: December 05, 2018 (last updated November 08, 2023)
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
0
Attacker Value
Unknown
CVE-2011-2767
Disclosure Date: August 26, 2018 (last updated November 08, 2023)
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
0