Skip to content
Noroxi

perl records

77 published records for vendor perl.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 1.3%
Pre-auth RCE
11
With a fix record
93.5%
Median publish → KEV
No record has entered KEV

All records

77 records
  • The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and f

    HighCVSS 7.5WeaponizedEPSS 63%

    perl · perlJan 4, 2013

  • Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

    CriticalCVSS 9.8No exploitEPSS 12%

    perl · perlDec 5, 2018

  • Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

    CriticalCVSS 9.8No exploitEPSS 12%

    perl · perlDec 7, 2018

  • Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a lar

    CriticalCVSS 9.8No exploitEPSS 11%

    perl · perlApr 17, 2018

  • Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windo

    CriticalCVSS 9.8No exploitEPSS 7%

    perl · perlSep 27, 2017

  • An issue was discovered in Perl 5.18 through 5.26.

    CriticalCVSS 9.8No exploitEPSS 6%

    perl · perlApr 17, 2018

  • Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

    CriticalCVSS 9.8No exploitEPSS 6%

    perl · perlDec 7, 2018

  • The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and po

    CriticalCVSS 9.8No exploitEPSS 5%

    perl · perlFeb 7, 2017

  • In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalat

    CriticalCVSS 9.8No exploitEPSS 3%

    perl · perlAug 22, 2023

  • Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process me

    CriticalCVSS 9.1No exploitEPSS 10%

    perl · perlDec 7, 2018

  • CVE-2026-9698
    39Monitor

    DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

    CriticalCVSS 9.8No exploitEPSS 1%

    perl · dbiJun 9, 2026

  • CVE-2026-4176
    39Monitor

    Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib

    CriticalCVSS 9.8No exploitEPSS 1%

    perl · perlMar 29, 2026

  • The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

    CriticalCVSS 9.8No exploitEPSS 1%

    Dec 8, 2024

  • DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders

    CriticalCVSS 9.8No exploitEPSS 0%

    perl · dbiJun 5, 2026

  • CVE-2026-8376
    39Monitor

    Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a

    CriticalCVSS 9.8No exploitEPSS 0%

    perl · perlMay 25, 2026

  • DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders

    CriticalCVSS 9.8No exploitEPSS 0%

    perl · dbiJul 7, 2026

  • Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attacker

    CriticalCVSS 9.1No exploitEPSS 6%

    perl · perlSep 19, 2017

  • The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situati

    CriticalCVSS 9.1No exploitEPSS 1%

    Mar 18, 2024

  • Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alterna

    CriticalCVSS 9.1No exploitEPSS 0%

    perl · perlJul 13, 2026

  • DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

    CriticalCVSS 9.1No exploitEPSS 0%

    perl · dbiJul 7, 2026

  • Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer ove

    HighCVSS 8.2No exploitEPSS 11%

    perl · perlJun 5, 2020

  • Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.

    HighCVSS 8.6No exploitEPSS 5%

    perl · perlJun 5, 2020

  • DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile

    HighCVSS 8.8No exploitEPSS 0%

    perl · dbiJul 7, 2026

  • CVE-2005-1349
    34Monitor

    Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter t

    HighCVSS 7.5Proof of conceptEPSS 13%

    perl · convert uulibMay 2, 2005

  • CVE-2016-2381
    33Monitor

    Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables

    HighCVSS 7.5No exploitEPSS 9%

    perl · perlApr 8, 2016