Vulnerabilities > Ingy

DATE CVE VULNERABILITY TITLE RISK
2014-06-04 CVE-2012-6143 Code Injection vulnerability in Ingy Spoon 0.24
Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
network
low complexity
ingy CWE-94
7.5
2012-09-09 CVE-2012-1152 USE of Externally-Controlled Format String vulnerability in Ingy Yaml::Libyaml 0.38
Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.
network
low complexity
ingy CWE-134
5.0