Vulnerabilities > Perl

DATE CVE VULNERABILITY TITLE RISK
2020-09-16 CVE-2020-14393 Out-Of-Bounds Write vulnerability in multiple products
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs.
local
low complexity
perl opensuse CWE-787
3.6
2020-09-16 CVE-2020-14392 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643.
local
low complexity
perl canonical opensuse CWE-119
2.1
2020-06-05 CVE-2020-12723 Classic Buffer Overflow vulnerability in Perl
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
network
low complexity
perl CWE-120
5.0
2020-06-05 CVE-2020-10878 Integer Overflow OR Wraparound vulnerability in multiple products
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.
network
low complexity
perl fedoraproject CWE-190
7.5
2020-06-05 CVE-2020-10543 Out-Of-Bounds Write vulnerability in multiple products
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
network
low complexity
perl fedoraproject CWE-787
6.4
2018-12-07 CVE-2018-18314 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
network
low complexity
perl canonical debian netapp redhat CWE-119
7.5
2018-12-07 CVE-2018-18313 Out-Of-Bounds Read vulnerability in multiple products
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
network
low complexity
perl canonical debian redhat netapp apple CWE-125
6.4
2018-12-07 CVE-2018-18311 Integer Overflow OR Wraparound vulnerability in multiple products
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
7.5
2018-12-05 CVE-2018-18312 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
network
low complexity
perl canonical debian redhat netapp CWE-119
7.5
2018-06-07 CVE-2018-12015 Link Following vulnerability in multiple products
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
network
low complexity
canonical debian perl archive apple netapp CWE-59
6.4