Записи perl
77 опубликованных записей вендора perl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,3 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 93,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-787 Out-of-bounds Write7
- CWE-20 Improper Input Validation6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-125 Out-of-bounds Read5
- CWE-189 Numeric Errors5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
77 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2012-6329Готовый эксплойт | The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fperl · perl · CWE-94 | Высокая7,5 | — | 63,5 % | 4 янв. 2013 г. |
43В плане | CVE-2018-18312Эксплойта нет | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-119 | Критическая9,8 | — | 12,1 % | 5 дек. 2018 г. |
43В плане | CVE-2018-18311Эксплойта нет | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-190 | Критическая9,8 | — | 11,7 % | 7 дек. 2018 г. |
42В плане | CVE-2018-6913Эксплойта нет | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a larperl · perl · CWE-787 | Критическая9,8 | — | 10,7 % | 17 апр. 2018 г. |
41В плане | CVE-2017-12814Эксплойта нет | Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windoperl · perl · CWE-119 | Критическая9,8 | — | 7,0 % | 27 сент. 2017 г. |
41В плане | CVE-2018-6797Эксплойта нет | An issue was discovered in Perl 5.18 through 5.26.perl · perl · CWE-787 | Критическая9,8 | — | 6,5 % | 17 апр. 2018 г. |
41В плане | CVE-2018-18314Эксплойта нет | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.perl · perl · CWE-119 | Критическая9,8 | — | 6,1 % | 7 дек. 2018 г. |
40В плане | CVE-2015-8608Эксплойта нет | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and poperl · perl · CWE-125 | Критическая9,8 | — | 4,6 % | 7 февр. 2017 г. |
40В плане | CVE-2022-48522Эксплойта нет | In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalatperl · perl · CWE-787 | Критическая9,8 | — | 2,6 % | 22 авг. 2023 г. |
39Наблюдать | CVE-2018-18313Эксплойта нет | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process meperl · perl · CWE-125 | Критическая9,1 | — | 9,5 % | 7 дек. 2018 г. |
39Наблюдать | CVE-2026-9698Эксплойта нет | DBI versions before 1.648 for Perl saved errors in a limited-sized bufferperl · dbi · CWE-787 | Критическая9,8 | — | 0,8 % | 9 июн. 2026 г. |
39Наблюдать | CVE-2026-4176Эксплойта нет | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlibperl · perl · CWE-1395 | Критическая9,8 | — | 0,8 % | 29 мар. 2026 г. |
39Наблюдать | CVE-2024-55564Эксплойта нет | The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.CWE-120 | Критическая9,8 | — | 0,5 % | 8 дек. 2024 г. |
39Наблюдать | CVE-2026-10879Эксплойта нет | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersperl · dbi · CWE-787 | Критическая9,8 | — | 0,5 % | 5 июн. 2026 г. |
39Наблюдать | CVE-2026-8376Эксплойта нет | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with aperl · perl · CWE-680 | Критическая9,8 | — | 0,5 % | 25 мая 2026 г. |
39Наблюдать | CVE-2026-14739Эксплойта нет | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholdersperl · dbi · CWE-787 | Критическая9,8 | — | 0,4 % | 7 июл. 2026 г. |
38Наблюдать | CVE-2017-12883Эксплойта нет | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackerperl · perl · CWE-119 | Критическая9,1 | — | 5,9 % | 19 сент. 2017 г. |
36Наблюдать | CVE-2021-47155Эксплойта нет | The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situatiCWE-284 | Критическая9,1 | — | 0,5 % | 18 мар. 2024 г. |
36Наблюдать | CVE-2026-13221Эксплойта нет | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternaperl · perl · CWE-190 | Критическая9,1 | — | 0,4 % | 13 июл. 2026 г. |
36Наблюдать | CVE-2026-14740Эксплойта нет | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentperl · dbi · CWE-125 | Критическая9,1 | — | 0,4 % | 7 июл. 2026 г. |
35Наблюдать | CVE-2020-10543Эксплойта нет | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer oveperl · perl · CWE-190 | Высокая8,2 | — | 11,3 % | 5 июн. 2020 г. |
35Наблюдать | CVE-2020-10878Эксплойта нет | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.perl · perl · CWE-190 | Высокая8,6 | — | 4,9 % | 5 июн. 2020 г. |
35Наблюдать | CVE-2026-14380Эксплойта нет | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profileperl · dbi · CWE-95 | Высокая8,8 | — | 0,5 % | 7 июл. 2026 г. |
34Наблюдать | CVE-2005-1349Proof of concept | Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter tperl · convert uulib | Высокая7,5 | — | 12,8 % | 2 мая 2005 г. |
33Наблюдать | CVE-2016-2381Эксплойта нет | Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variablesperl · perl · CWE-20 | Высокая7,5 | — | 9,1 % | 8 апр. 2016 г. |
- CVE-2012-632949В плане
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and f
ВысокаяCVSS 7,5Готовый эксплойтEPSS 63 %perl · perl4 янв. 2013 г.
- CVE-2018-1831243В плане
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %perl · perl5 дек. 2018 г.
- CVE-2018-1831143В плане
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %perl · perl7 дек. 2018 г.
- CVE-2018-691342В плане
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a lar
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %perl · perl17 апр. 2018 г.
- CVE-2017-1281441В плане
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windo
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %perl · perl27 сент. 2017 г.
- CVE-2018-679741В плане
An issue was discovered in Perl 5.18 through 5.26.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %perl · perl17 апр. 2018 г.
- CVE-2018-1831441В плане
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %perl · perl7 дек. 2018 г.
- CVE-2015-860840В плане
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and po
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %perl · perl7 февр. 2017 г.
- CVE-2022-4852240В плане
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalat
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %perl · perl22 авг. 2023 г.
- CVE-2018-1831339Наблюдать
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process me
КритическаяCVSS 9,1Эксплойта нетEPSS 10 %perl · perl7 дек. 2018 г.
- CVE-2026-969839Наблюдать
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %perl · dbi9 июн. 2026 г.
- CVE-2026-417639Наблюдать
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %perl · perl29 мар. 2026 г.
- CVE-2024-5556439Наблюдать
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %8 дек. 2024 г.
- CVE-2026-1087939Наблюдать
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %perl · dbi5 июн. 2026 г.
- CVE-2026-837639Наблюдать
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %perl · perl25 мая 2026 г.
- CVE-2026-1473939Наблюдать
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %perl · dbi7 июл. 2026 г.
- CVE-2017-1288338Наблюдать
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attacker
КритическаяCVSS 9,1Эксплойта нетEPSS 6 %perl · perl19 сент. 2017 г.
- CVE-2021-4715536Наблюдать
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situati
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %18 мар. 2024 г.
- CVE-2026-1322136Наблюдать
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alterna
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %perl · perl13 июл. 2026 г.
- CVE-2026-1474036Наблюдать
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %perl · dbi7 июл. 2026 г.
- CVE-2020-1054335Наблюдать
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer ove
ВысокаяCVSS 8,2Эксплойта нетEPSS 11 %perl · perl5 июн. 2020 г.
- CVE-2020-1087835Наблюдать
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation.
ВысокаяCVSS 8,6Эксплойта нетEPSS 5 %perl · perl5 июн. 2020 г.
- CVE-2026-1438035Наблюдать
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %perl · dbi7 июл. 2026 г.
- CVE-2005-134934Наблюдать
Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter t
ВысокаяCVSS 7,5Proof of conceptEPSS 13 %perl · convert uulib2 мая 2005 г.
- CVE-2016-238133Наблюдать
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %perl · perl8 апр. 2016 г.