Show filters
141 Total Results
Displaying 31-40 of 141
Sort by:
Attacker Value
Unknown
CVE-2018-10860
Disclosure Date: June 29, 2018 (last updated November 26, 2024)
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
0
Attacker Value
Unknown
CVE-2018-12015
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
0
Attacker Value
Unknown
CVE-2018-6798
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
0
Attacker Value
Unknown
CVE-2018-6913
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
0
Attacker Value
Unknown
CVE-2018-6797
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
0
Attacker Value
Unknown
CVE-2014-2277
Disclosure Date: October 17, 2017 (last updated November 26, 2024)
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.
0
Attacker Value
Unknown
CVE-2017-12814
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.
0
Attacker Value
Unknown
CVE-2017-12837
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
0
Attacker Value
Unknown
CVE-2017-12883
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
0
Attacker Value
Unknown
CVE-2016-10374
Disclosure Date: May 17, 2017 (last updated November 26, 2024)
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.
0