Search CVE reports


Toggle filters

31 – 40 of 238 results


CVE-2024-2467

Medium priority
Vulnerable

A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would...

1 affected package

libcrypt-openssl-rsa-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-rsa-perl Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-23525

Medium priority

Some fixes available 3 of 4

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

1 affected package

libspreadsheet-parsexlsx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parsexlsx-perl Not affected Fixed Fixed Ignored
Show less packages

CVE-2024-22368

Medium priority

Some fixes available 3 of 4

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on...

1 affected package

libspreadsheet-parsexlsx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parsexlsx-perl Not affected Fixed Fixed Ignored
Show less packages

CVE-2024-13939

Medium priority
Needs evaluation

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different,...

1 affected package

libstring-compare-constanttime-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstring-compare-constanttime-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-10224

Medium priority
Fixed

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|"...

1 affected package

libmodule-scandeps-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmodule-scandeps-perl Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-7101

Medium priority

Some fixes available 5 of 7

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a...

1 affected package

libspreadsheet-parseexcel-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parseexcel-perl Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-47100

Medium priority
Not affected

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Not affected Not affected Not affected
Show less packages

CVE-2023-47039

Negligible priority
Ignored

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter,...

3 affected packages

perl, perl6, raku

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Ignored Ignored Ignored
perl6 Not in release Ignored Ignored
raku Not in release Not in release Ignored
Show less packages

CVE-2023-47038

Medium priority

Some fixes available 7 of 14

A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.

3 affected packages

perl, perl6, raku

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Fixed Fixed Not affected
perl6 Not in release Not in release Needs evaluation Needs evaluation
raku Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2023-31486

Medium priority
Ignored

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

2 affected packages

libhttp-tiny-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhttp-tiny-perl Ignored Ignored Ignored
perl Ignored Ignored Ignored
Show less packages