Search CVE reports


Toggle filters

41 – 50 of 238 results


CVE-2023-31485

Medium priority
Ignored

GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.

1 affected package

libgitlab-api-v4-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgitlab-api-v4-perl Not affected Ignored Ignored Ignored
Show less packages

CVE-2023-31484

Medium priority
Fixed

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Fixed Fixed
Show less packages

CVE-2023-24038

Medium priority

Some fixes available 6 of 7

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

1 affected package

libhtml-stripscripts-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhtml-stripscripts-perl Fixed Fixed Fixed
Show less packages

CVE-2022-48623

Medium priority

Some fixes available 2 of 4

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.

1 affected package

libcpanel-json-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcpanel-json-xs-perl Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2022-48522

Low priority
Fixed

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Not affected Not affected
Show less packages

CVE-2022-31081

Medium priority

Some fixes available 6 of 7

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It...

1 affected package

libhttp-daemon-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhttp-daemon-perl Fixed Fixed Fixed
Show less packages

CVE-2022-23935

Medium priority
Vulnerable

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

1 affected package

libimage-exiftool-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libimage-exiftool-perl Not affected Needs evaluation Vulnerable Vulnerable
Show less packages

CVE-2021-47208

Medium priority
Needs evaluation

The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

1 affected package

libmojolicious-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmojolicious-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-47155

Medium priority
Needs evaluation

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

1 affected package

libnetwork-ipv4addr-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnetwork-ipv4addr-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-47154

Medium priority

Some fixes available 1 of 3

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on...

1 affected package

libnet-cidr-lite-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-cidr-lite-perl Not affected Not affected Fixed Needs evaluation
Show less packages