perl records
77 published records for vendor perl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.3%
- Pre-auth RCE
- 11
- With a fix record
- 93.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-787 Out-of-bounds Write7
- CWE-20 Improper Input Validation6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-125 Out-of-bounds Read5
- CWE-189 Numeric Errors5
The weakness classes this vendor ships most often: where to look.
CWEAll records
77 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2012-6329Weaponized | The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fperl · perl · CWE-94 | High7.5 | — | 63.5% | Jan 4, 2013 |
43Plan | CVE-2018-18312No exploit | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-119 | Critical9.8 | — | 12.1% | Dec 5, 2018 |
43Plan | CVE-2018-18311No exploit | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-190 | Critical9.8 | — | 11.7% | Dec 7, 2018 |
42Plan | CVE-2018-6913No exploit | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a larperl · perl · CWE-787 | Critical9.8 | — | 10.7% | Apr 17, 2018 |
41Plan | CVE-2017-12814No exploit | Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windoperl · perl · CWE-119 | Critical9.8 | — | 7.0% | Sep 27, 2017 |
41Plan | CVE-2018-6797No exploit | An issue was discovered in Perl 5.18 through 5.26.perl · perl · CWE-787 | Critical9.8 | — | 6.5% | Apr 17, 2018 |
41Plan | CVE-2018-18314No exploit | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-119 | Critical9.8 | — | 6.1% | Dec 7, 2018 |
40Plan | CVE-2015-8608No exploit | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and poperl · perl · CWE-125 | Critical9.8 | — | 4.6% | Feb 7, 2017 |
40Plan | CVE-2022-48522No exploit | In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalatperl · perl · CWE-787 | Critical9.8 | — | 2.6% | Aug 22, 2023 |
39Monitor | CVE-2018-18313No exploit | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process meperl · perl · CWE-125 | Critical9.1 | — | 9.5% | Dec 7, 2018 |
39Monitor | CVE-2026-9698No exploit | DBI versions before 1.648 for Perl saved errors in a limited-sized bufferperl · dbi · CWE-787 | Critical9.8 | — | 0.8% | Jun 9, 2026 |
39Monitor | CVE-2026-4176No exploit | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlibperl · perl · CWE-1395 | Critical9.8 | — | 0.8% | Mar 29, 2026 |
39Monitor | CVE-2024-55564No exploit | The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.CWE-120 | Critical9.8 | — | 0.5% | Dec 8, 2024 |
39Monitor | CVE-2026-10879No exploit | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersperl · dbi · CWE-787 | Critical9.8 | — | 0.5% | Jun 5, 2026 |
39Monitor | CVE-2026-8376No exploit | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with aperl · perl · CWE-680 | Critical9.8 | — | 0.5% | May 25, 2026 |
39Monitor | CVE-2026-14739No exploit | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholdersperl · dbi · CWE-787 | Critical9.8 | — | 0.4% | Jul 7, 2026 |
38Monitor | CVE-2017-12883No exploit | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackerperl · perl · CWE-119 | Critical9.1 | — | 5.9% | Sep 19, 2017 |
36Monitor | CVE-2021-47155No exploit | The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situatiCWE-284 | Critical9.1 | — | 0.5% | Mar 18, 2024 |
36Monitor | CVE-2026-13221No exploit | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternaperl · perl · CWE-190 | Critical9.1 | — | 0.4% | Jul 13, 2026 |
36Monitor | CVE-2026-14740No exploit | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentperl · dbi · CWE-125 | Critical9.1 | — | 0.4% | Jul 7, 2026 |
35Monitor | CVE-2020-10543No exploit | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer oveperl · perl · CWE-190 | High8.2 | — | 11.3% | Jun 5, 2020 |
35Monitor | CVE-2020-10878No exploit | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.perl · perl · CWE-190 | High8.6 | — | 4.9% | Jun 5, 2020 |
35Monitor | CVE-2026-14380No exploit | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profileperl · dbi · CWE-95 | High8.8 | — | 0.5% | Jul 7, 2026 |
34Monitor | CVE-2005-1349Proof of concept | Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter tperl · convert uulib | High7.5 | — | 12.8% | May 2, 2005 |
33Monitor | CVE-2016-2381No exploit | Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variablesperl · perl · CWE-20 | High7.5 | — | 9.1% | Apr 8, 2016 |
- CVE-2012-632949Plan
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and f
HighCVSS 7.5WeaponizedEPSS 63%perl · perlJan 4, 2013
- CVE-2018-1831243Plan
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CriticalCVSS 9.8No exploitEPSS 12%perl · perlDec 5, 2018
- CVE-2018-1831143Plan
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CriticalCVSS 9.8No exploitEPSS 12%perl · perlDec 7, 2018
- CVE-2018-691342Plan
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a lar
CriticalCVSS 9.8No exploitEPSS 11%perl · perlApr 17, 2018
- CVE-2017-1281441Plan
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windo
CriticalCVSS 9.8No exploitEPSS 7%perl · perlSep 27, 2017
- CVE-2018-679741Plan
An issue was discovered in Perl 5.18 through 5.26.
CriticalCVSS 9.8No exploitEPSS 6%perl · perlApr 17, 2018
- CVE-2018-1831441Plan
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CriticalCVSS 9.8No exploitEPSS 6%perl · perlDec 7, 2018
- CVE-2015-860840Plan
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and po
CriticalCVSS 9.8No exploitEPSS 5%perl · perlFeb 7, 2017
- CVE-2022-4852240Plan
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalat
CriticalCVSS 9.8No exploitEPSS 3%perl · perlAug 22, 2023
- CVE-2018-1831339Monitor
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process me
CriticalCVSS 9.1No exploitEPSS 10%perl · perlDec 7, 2018
- CVE-2026-969839Monitor
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
CriticalCVSS 9.8No exploitEPSS 1%perl · dbiJun 9, 2026
- CVE-2026-417639Monitor
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
CriticalCVSS 9.8No exploitEPSS 1%perl · perlMar 29, 2026
- CVE-2024-5556439Monitor
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
CriticalCVSS 9.8No exploitEPSS 1%Dec 8, 2024
- CVE-2026-1087939Monitor
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
CriticalCVSS 9.8No exploitEPSS 0%perl · dbiJun 5, 2026
- CVE-2026-837639Monitor
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a
CriticalCVSS 9.8No exploitEPSS 0%perl · perlMay 25, 2026
- CVE-2026-1473939Monitor
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
CriticalCVSS 9.8No exploitEPSS 0%perl · dbiJul 7, 2026
- CVE-2017-1288338Monitor
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attacker
CriticalCVSS 9.1No exploitEPSS 6%perl · perlSep 19, 2017
- CVE-2021-4715536Monitor
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situati
CriticalCVSS 9.1No exploitEPSS 1%Mar 18, 2024
- CVE-2026-1322136Monitor
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alterna
CriticalCVSS 9.1No exploitEPSS 0%perl · perlJul 13, 2026
- CVE-2026-1474036Monitor
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
CriticalCVSS 9.1No exploitEPSS 0%perl · dbiJul 7, 2026
- CVE-2020-1054335Monitor
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer ove
HighCVSS 8.2No exploitEPSS 11%perl · perlJun 5, 2020
- CVE-2020-1087835Monitor
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.
HighCVSS 8.6No exploitEPSS 5%perl · perlJun 5, 2020
- CVE-2026-1438035Monitor
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
HighCVSS 8.8No exploitEPSS 0%perl · dbiJul 7, 2026
- CVE-2005-134934Monitor
Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter t
HighCVSS 7.5Proof of conceptEPSS 13%perl · convert uulibMay 2, 2005
- CVE-2016-238133Monitor
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables
HighCVSS 7.5No exploitEPSS 9%perl · perlApr 8, 2016