Search CVE reports


Toggle filters

71 – 80 of 238 results


CVE-2018-9246

Medium priority
Needs evaluation

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the...

1 affected package

libpgobject-util-dbadmin-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpgobject-util-dbadmin-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-6913

Medium priority
Fixed

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2018-6798

Medium priority
Fixed

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2018-6797

Medium priority

Some fixes available 2 of 3

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2018-25107

Medium priority
Needs evaluation

The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits.

1 affected package

libcrypt-random-source-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-random-source-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-25100

Medium priority
Needs evaluation

The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-25099

Medium priority
Needs evaluation

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

1 affected package

libcryptx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcryptx-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-25052

Medium priority
Needs evaluation

A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component Session ID...

1 affected package

libcatalyst-plugin-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-session-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-18898

Medium priority

Some fixes available 5 of 6

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

1 affected package

libemail-address-list-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-list-perl Fixed Fixed
Show less packages

CVE-2018-18314

Medium priority
Fixed

Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages