Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

71 – 80 of 204 results


CVE-2018-6797

Medium priority

Some fixes available 2 of 3

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

1 affected packages

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2008-7319

Medium priority
Vulnerable

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection...

1 affected packages

libnet-ping-external-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libnet-ping-external-perl Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-16248

Medium priority
Vulnerable

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only...

1 affected packages

libcatalyst-plugin-static-simple-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libcatalyst-plugin-static-simple-perl Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2014-2277

Low priority
Ignored

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

1 affected packages

perltidy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perltidy Not affected Not affected
Show less packages

CVE-2008-7315

Medium priority
Vulnerable

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

1 affected packages

libui-dialog-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libui-dialog-perl Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2017-12814

Medium priority
Not affected

Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.

1 affected packages

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Not affected
Show less packages

CVE-2017-12883

Medium priority
Fixed

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a...

1 affected packages

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2017-12837

Medium priority
Fixed

Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a...

1 affected packages

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
perl Fixed
Show less packages

CVE-2010-3845

Unknown priority
Ignored

libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.

1 affected packages

libapache-authenhook-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-authenhook-perl
Show less packages

CVE-2017-10789

Low priority

Some fixes available 1 of 5

The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows...

1 affected packages

libdbd-mysql-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libdbd-mysql-perl Not affected Not affected Not affected Not affected Fixed
Show less packages