Search CVE reports


Toggle filters

91 – 100 of 211 results


CVE-2017-6512

Low priority

Some fixes available 2 of 4

Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2017-0374

Medium priority
Vulnerable

lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.

1 affected package

libconfig-model-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libconfig-model-perl Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-0373

Medium priority
Vulnerable

The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a...

1 affected package

libconfig-model-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libconfig-model-perl Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10374

Low priority
Vulnerable

perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which...

1 affected package

perltidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perltidy Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-1249

Low priority

Some fixes available 1 of 4

The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE...

1 affected package

libdbd-mysql-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libdbd-mysql-perl Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2015-8608

Negligible priority
Not affected

The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl
Show less packages

CVE-2016-9181

Medium priority
Vulnerable

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service...

1 affected package

libimage-info-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libimage-info-perl Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-9180

Low priority
Vulnerable

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

1 affected package

libxml-twig-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libxml-twig-perl Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2016-1251

Low priority

Some fixes available 1 of 4

There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.

1 affected package

libdbd-mysql-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libdbd-mysql-perl Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2015-8978

Low priority
Fixed

In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined as consisting of 10 of the previous entity, with the document consisting of a...

1 affected package

libsoap-lite-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libsoap-lite-perl Not affected Not affected
Show less packages