Search CVE reports


Toggle filters

151 – 160 of 244 results


CVE-2013-7329

Medium priority
Ignored

The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the dump_html function.

1 affected package

libcgi-application-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcgi-application-perl
Show less packages

CVE-2014-4330

Low priority

Some fixes available 2 of 3

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2014-5269

Medium priority
Ignored

Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to...

1 affected package

libplack-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-perl Not affected
Show less packages

CVE-2014-5260

Low priority
Ignored

The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.

1 affected package

libxml-dt-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml-dt-perl Not affected
Show less packages

CVE-2014-1474

Medium priority

Not in release

Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address.

1 affected package

libemail-address-list-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-list-perl
Show less packages

CVE-2014-4720

Low priority
Ignored

Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase," a different...

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-perl Not affected
Show less packages

CVE-2014-0477

Low priority
Ignored

The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC 2822 address.

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-perl Not affected
Show less packages

CVE-2013-1841

Low priority
Vulnerable

Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address, which might allow remote attackers to bypass ACL restrictions via the hostname parameter.

1 affected package

libnet-server-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-server-perl Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2012-6143

Low priority
Ignored

Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

1 affected package

libspoon-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspoon-perl Not in release
Show less packages

CVE-2012-5572

Medium priority
Ignored

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different...

1 affected package

libdancer-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdancer-perl
Show less packages