Show filters
333 Total Results
Displaying 291-300 of 333
Sort by:
Attacker Value
Unknown

CVE-2004-2022

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.
0
Attacker Value
Unknown

CVE-2004-0452

Disclosure Date: December 21, 2004 (last updated October 04, 2023)
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.
0
Attacker Value
Unknown

CVE-2004-0241

Disclosure Date: November 23, 2004 (last updated October 04, 2023)
X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.
0
Attacker Value
Unknown

CVE-2004-1678

Disclosure Date: September 13, 2004 (last updated October 04, 2023)
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.
0
Attacker Value
Unknown

CVE-2004-0377

Disclosure Date: May 04, 2004 (last updated October 03, 2023)
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.
0
Attacker Value
Unknown

CVE-2003-1287

Disclosure Date: December 31, 2003 (last updated October 03, 2023)
Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.
0
Attacker Value
Unknown

CVE-2003-0900

Disclosure Date: December 31, 2003 (last updated October 03, 2023)
Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.
0
Attacker Value
Unknown

CVE-2003-1426

Disclosure Date: December 31, 2003 (last updated October 03, 2023)
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.
0
Attacker Value
Unknown

CVE-2003-0770

Disclosure Date: September 22, 2003 (last updated October 03, 2023)
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.
0
Attacker Value
Unknown

CVE-2003-0562

Disclosure Date: August 27, 2003 (last updated October 03, 2023)
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
0