Search CVE reports


Toggle filters

71 – 80 of 211 results


CVE-2011-2767

Medium priority
Fixed

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the...

1 affected package

libapache2-mod-perl2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache2-mod-perl2 Fixed Fixed
Show less packages

CVE-2018-10860

Medium priority
Fixed

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive...

1 affected package

libarchive-zip-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libarchive-zip-perl Fixed Fixed
Show less packages

CVE-2018-12558

Low priority
Vulnerable

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30...

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libemail-address-perl Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-9246

Medium priority
Needs evaluation

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the...

1 affected package

libpgobject-util-dbadmin-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpgobject-util-dbadmin-perl Not affected Not affected Not affected Needs evaluation Not in release
Show less packages

CVE-2018-12015

Medium priority
Fixed

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed Fixed
Show less packages

CVE-2018-6913

Medium priority
Fixed

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2018-6798

Medium priority
Fixed

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2018-6797

Medium priority

Some fixes available 2 of 3

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2008-7319

Medium priority
Vulnerable

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection...

1 affected package

libnet-ping-external-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libnet-ping-external-perl Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-16248

Medium priority
Vulnerable

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only...

1 affected package

libcatalyst-plugin-static-simple-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libcatalyst-plugin-static-simple-perl Not affected Not affected Not affected Not affected Vulnerable
Show less packages