Show filters
333 Total Results
Displaying 91-100 of 333
Sort by:
Attacker Value
Unknown
CVE-2018-18312
Disclosure Date: December 05, 2018 (last updated November 08, 2023)
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
0
Attacker Value
Unknown
CVE-2011-2767
Disclosure Date: August 26, 2018 (last updated November 08, 2023)
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
0
Attacker Value
Unknown
CVE-2018-10860
Disclosure Date: June 29, 2018 (last updated October 06, 2023)
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
0
Attacker Value
Unknown
CVE-2018-12558
Disclosure Date: June 20, 2018 (last updated October 06, 2023)
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
0
Attacker Value
Unknown
CVE-2018-9246
Disclosure Date: June 08, 2018 (last updated October 06, 2023)
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.
0
Attacker Value
Unknown
CVE-2018-12015
Disclosure Date: June 07, 2018 (last updated October 06, 2023)
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
0
Attacker Value
Unknown
CVE-2014-0931
Disclosure Date: April 20, 2018 (last updated October 06, 2023)
Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integrations components in IBM Rational ClearCase 7.1.0.x, 7.1.1.x, 7.1.2 through 7.1.2.13, 8.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92263.
0
Attacker Value
Unknown
CVE-2018-6798
Disclosure Date: April 17, 2018 (last updated October 06, 2023)
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
0
Attacker Value
Unknown
CVE-2018-6913
Disclosure Date: April 17, 2018 (last updated October 06, 2023)
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
0
Attacker Value
Unknown
CVE-2018-6797
Disclosure Date: April 17, 2018 (last updated October 06, 2023)
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
0