Search CVE reports


Toggle filters

191 – 200 of 248 results


CVE-2011-2483

Medium priority

Some fixes available 8 of 14

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to...

7 affected packages

john, libcrypt-eksblowfish-perl, php5, postgresql-8.2, postgresql-8.3...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
john
libcrypt-eksblowfish-perl
php5
postgresql-8.2
postgresql-8.3
postgresql-8.4
postgresql-9.1
Show all 7 packages Show less packages

CVE-2011-0633

Medium priority
Ignored

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of...

1 affected package

libwww-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libwww-perl
Show less packages

CVE-2011-0761

Low priority
Ignored

Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir,...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2011-1841

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl
Show less packages

CVE-2010-4803

Medium priority
Not affected

Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl
Show less packages

CVE-2010-4802

Medium priority
Not affected

Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl
Show less packages

CVE-2009-5074

Medium priority
Not affected

Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250 has unknown impact and attack vectors.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl
Show less packages

CVE-2011-1589

Medium priority
Ignored

Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl
Show less packages

CVE-2011-1487

Low priority

Some fixes available 3 of 4

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2010-4334

Medium priority
Ignored

The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended...

1 affected package

libio-socket-ssl-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libio-socket-ssl-perl
Show less packages