Show filters
333 Total Results
Displaying 21-30 of 333
Sort by:
Attacker Value
Unknown

CVE-2018-25100

Disclosure Date: March 24, 2024 (last updated August 02, 2024)
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.
0
Attacker Value
Unknown

CVE-2021-47155

Disclosure Date: March 18, 2024 (last updated August 30, 2024)
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
0
Attacker Value
Unknown

CVE-2021-47154

Disclosure Date: March 18, 2024 (last updated November 16, 2024)
The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
0
Attacker Value
Unknown

CVE-2018-25099

Disclosure Date: March 18, 2024 (last updated August 29, 2024)
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.
0
Attacker Value
Unknown

CVE-2024-25021

Disclosure Date: February 22, 2024 (last updated February 23, 2024)
IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.
0
Attacker Value
Unknown

CVE-2023-52431

Disclosure Date: February 13, 2024 (last updated October 22, 2024)
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).
Attacker Value
Unknown

CVE-2022-48623

Disclosure Date: February 13, 2024 (last updated October 31, 2024)
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
Attacker Value
Unknown

CVE-2023-6078

Disclosure Date: February 01, 2024 (last updated February 10, 2024)
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
Attacker Value
Unknown

CVE-2024-23525

Disclosure Date: January 18, 2024 (last updated January 25, 2024)
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
Attacker Value
Unknown

CVE-2024-22368

Disclosure Date: January 09, 2024 (last updated January 17, 2024)
The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.