Search CVE reports


Toggle filters

61 – 70 of 207 results


CVE-2019-1010263

Medium priority
Needs evaluation

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector...

1 affected package

libcrypt-jwt-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-jwt-perl Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2018-18898

Medium priority

Some fixes available 5 of 6

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

1 affected package

libemail-address-list-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-list-perl Fixed Fixed
Show less packages

CVE-2018-18314

Medium priority
Fixed

Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18313

Medium priority
Fixed

Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18312

Medium priority
Fixed

Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18311

Medium priority
Fixed

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2011-2767

Medium priority
Fixed

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the...

1 affected package

libapache2-mod-perl2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-perl2 Fixed
Show less packages

CVE-2018-10860

Medium priority
Fixed

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive...

1 affected package

libarchive-zip-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive-zip-perl Fixed
Show less packages

CVE-2018-12558

Low priority
Vulnerable

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30...

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-perl Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-9246

Medium priority
Needs evaluation

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the...

1 affected package

libpgobject-util-dbadmin-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpgobject-util-dbadmin-perl Not affected Not affected Not affected Needs evaluation
Show less packages