Search CVE reports


Toggle filters

181 – 190 of 248 results


CVE-2012-1151

Medium priority

Some fixes available 5 of 9

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string...

1 affected package

libdbd-pg-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdbd-pg-perl
Show less packages

CVE-2012-2451

Medium priority

Some fixes available 4 of 5

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third...

1 affected package

libconfig-inifiles-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libconfig-inifiles-perl
Show less packages

CVE-2011-5060

Low priority
Ignored

The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite...

1 affected package

libpar-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpar-perl
Show less packages

CVE-2011-4114

Low priority
Ignored

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to...

2 affected packages

libpar-packer-perl, libpar-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpar-packer-perl
libpar-perl
Show less packages

CVE-2011-3597

Low priority

Some fixes available 3 of 10

Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.

2 affected packages

libdigest-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdigest-perl
perl
Show less packages

CVE-2011-2939

Low priority

Some fixes available 1 of 3

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2011-4616

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater...

1 affected package

libhtml-template-pro-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhtml-template-pro-perl
Show less packages

CVE-2011-3599

Negligible priority

Not in release

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed...

1 affected package

libcrypt-dsa-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-dsa-perl
Show less packages

CVE-2011-2766

Medium priority

Some fixes available 2 of 3

The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via...

1 affected package

libfcgi-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfcgi-perl
Show less packages

CVE-2011-2201

Low priority
Ignored

The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism...

1 affected package

libdata-formvalidator-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdata-formvalidator-perl
Show less packages