Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Perl CRITICAL 9.1
CVE-2017-12883EPSS 6%

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disc…

Fix: after 5.24.2
Fix from $2,300 2017-09-19
Perl HIGH 7.5
CVE-2017-12837EPSS 6%

Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to…

Fix: after 5.24.2
Fix from $1,950 2017-09-19
Perl CRITICAL 9.8
CVE-2015-8608

The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly ex…

Patch available
Fix from $2,300 2017-02-07
Perl HIGH 7.8
CVE-2016-6185

The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execu…

Fix: 5.24.1 / 5.25.3+
Fix from $1,950 2016-08-02
Perl HIGH 7.5
CVE-2016-2381EPSS 9%

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

Fix: 5.23.9 / 12.1.2.0.4+
Fix from $1,950 2016-04-08
Perl HIGH 7.5
CVE-2013-7422

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to ex…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Cgi Application Module MEDIUM 5.0
CVE-2013-7329

The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive inform…

Fix: after 4.50
Fix from $1,600 2014-10-06
Perl HIGH 7.5
CVE-2013-1667

The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via …

Mitigation only
Fix from $1,950 2013-03-14
Perl HIGH 7.5
CVE-2012-6329EPSS 62%

The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qual…

Fix: after 5.16.2
Fix from $1,950 2013-01-04
Perl HIGH 7.5
CVE-2012-5195

Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 all…

Patch available
Fix from $1,950 2012-12-18
Perl MEDIUM 5.0
CVE-2012-1151

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL da…

Fix: after 2.18.1
Fix from $1,600 2012-09-09
Perl MEDIUM 5.1
CVE-2011-2939

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context…

Fix: after 5.14.2
Fix from $1,600 2012-01-13
Perl MEDIUM 5.0
CVE-2011-0761EPSS 9%

Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability…

No fix yet
Fix from $1,600 2011-05-13
Perl MEDIUM 5.0
CVE-2011-1487EPSS 9%

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not appl…

Patch available
Fix from $1,600 2011-04-11
Perl MEDIUM 5.0
CVE-2010-1158

Integer overflow in the regular expression engine in Perl 5.8.x allows context-dependent attackers to cause a denial of service (stack consumption an…

No fix yet
Fix from $1,600 2010-04-20
Perl MEDIUM 5.0
CVE-2009-3626

Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint…

Patch available
Fix from $1,600 2009-10-29
File\ MEDIUM 6.9
CVE-2008-5302

Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary …

No fix yet
Fix from $1,600 2008-12-01
File\ MEDIUM 6.9
CVE-2008-5303

Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symli…

No fix yet
Fix from $1,600 2008-12-01
Perl MEDIUM 5.0
CVE-2008-1927

Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted r…

Mitigation only
Fix from $1,600 2008-04-24
Convert Uulib HIGH 7.5
CVE-2005-1349EPSS 13%

Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read …

Fix: after 1.050
Fix from $1,950 2005-05-02
Cgi Lite MEDIUM 5.0
CVE-2003-1365

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?",…

No fix yet
Fix from $1,600 2003-12-31
Perl MEDIUM 5.5
CVE-1999-1386

Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink…

Fix: after 5.004_04
Fix from $1,600 1999-12-31