Vulnerabilities > Perl > Perl

DATE CVE VULNERABILITY TITLE RISK
2024-01-02 CVE-2023-47039 Out-of-bounds Write vulnerability in Perl
A vulnerability was found in Perl.
local
low complexity
perl CWE-787
7.8
2023-12-18 CVE-2023-47038 Out-of-bounds Write vulnerability in Perl 5.34.0
A vulnerability was found in perl.
local
low complexity
perl CWE-787
7.8
2023-12-02 CVE-2023-47100 Improper Handling of Exceptional Conditions vulnerability in Perl
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled.
network
low complexity
perl CWE-755
critical
9.8
2023-08-22 CVE-2022-48522 Out-of-bounds Write vulnerability in Perl 5.34.0
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
network
low complexity
perl CWE-787
critical
9.8
2023-04-29 CVE-2023-31484 Improper Certificate Validation vulnerability in multiple products
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
network
high complexity
cpanpm-project perl CWE-295
8.1
2023-04-29 CVE-2023-31486 Improper Certificate Validation vulnerability in multiple products
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
network
high complexity
http perl CWE-295
8.1
2020-06-05 CVE-2020-12723 Classic Buffer Overflow vulnerability in multiple products
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
network
low complexity
perl netapp fedoraproject opensuse oracle CWE-120
7.5
2020-06-05 CVE-2020-10878 Integer Overflow or Wraparound vulnerability in multiple products
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.
network
low complexity
perl fedoraproject opensuse netapp oracle CWE-190
8.6
2020-06-05 CVE-2020-10543 Integer Overflow or Wraparound vulnerability in multiple products
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
network
low complexity
perl fedoraproject opensuse oracle CWE-190
8.2
2018-12-07 CVE-2018-18314 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
network
low complexity
perl canonical debian netapp redhat CWE-119
critical
9.8