Search CVE reports


Toggle filters

71 – 80 of 207 results


CVE-2018-12015

Medium priority
Fixed

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-6913

Medium priority
Fixed

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2018-6798

Medium priority
Fixed

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2018-6797

Medium priority

Some fixes available 2 of 3

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2008-7319

Medium priority
Vulnerable

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection...

1 affected package

libnet-ping-external-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-ping-external-perl Not in release Not in release Not in release Not in release
Show less packages

CVE-2017-16248

Medium priority
Vulnerable

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a ‘.’ character anywhere in the pathname, which differs from the intended policy of allowing access only...

1 affected package

libcatalyst-plugin-static-simple-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-static-simple-perl Not affected Not affected Not affected Not affected
Show less packages

CVE-2014-2277

Low priority
Ignored

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

1 affected package

perltidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perltidy Not affected
Show less packages

CVE-2008-7315

Medium priority
Vulnerable

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

1 affected package

libui-dialog-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libui-dialog-perl Not affected Not affected Not affected Not in release
Show less packages

CVE-2017-12814

Medium priority
Not affected

Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2017-12883

Medium priority
Fixed

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages