Search CVE reports


Toggle filters

231 – 240 of 248 results


CVE-2007-2383

Low priority
Ignored

The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves...

1 affected package

libhtml-prototype-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhtml-prototype-perl
Show less packages

CVE-2007-1349

Medium priority
Fixed

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource...

1 affected package

libapache2-mod-perl2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-perl2
Show less packages

CVE-2006-0053

Medium priority
Not affected

Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.

1 affected package

libimager-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libimager-perl
Show less packages

CVE-2006-1280

Medium priority
Fixed

CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.

1 affected package

libcgi-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcgi-session-perl
Show less packages

CVE-2006-1279

Medium priority
Fixed

CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.

1 affected package

libcgi-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcgi-session-perl
Show less packages

CVE-2006-0898

Medium priority
Fixed

Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such...

1 affected package

libcrypt-cbc-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-cbc-perl
Show less packages

CVE-2005-4536

Medium priority
Fixed

Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on...

1 affected package

libmail-audit-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmail-audit-perl
Show less packages

CVE-2005-3962

Medium priority
Fixed

Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values,...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2005-0106

Medium priority
Fixed

SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

1 affected package

libnet-ssleay-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-ssleay-perl
Show less packages

CVE-2005-1349

Medium priority
Not affected

Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.

1 affected package

libconvert-uulib-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libconvert-uulib-perl
Show less packages