Search CVE reports
21 – 30 of 211 results
CVE-2024-23525
Medium prioritySome fixes available 3 of 4
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
1 affected package
libspreadsheet-parsexlsx-perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libspreadsheet-parsexlsx-perl | Not affected | Fixed | Fixed | Ignored | Ignored |
CVE-2024-22368
Medium prioritySome fixes available 3 of 4
The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on...
1 affected package
libspreadsheet-parsexlsx-perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libspreadsheet-parsexlsx-perl | Not affected | Fixed | Fixed | Ignored | Ignored |
CVE-2023-7101
Medium prioritySome fixes available 5 of 7
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a...
1 affected package
libspreadsheet-parseexcel-perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libspreadsheet-parseexcel-perl | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2023-47100
Medium priorityIn Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
1 affected package
perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
perl | — | Not affected | Not affected | Not affected | Not affected |
CVE-2023-47039
Negligible priorityA vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter,...
3 affected packages
perl, perl6, raku
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
perl | — | Ignored | Ignored | Ignored | Ignored |
perl6 | — | Not in release | Ignored | Ignored | Ignored |
raku | — | Not in release | Not in release | Ignored | Ignored |
CVE-2023-47038
Medium prioritySome fixes available 6 of 12
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
3 affected packages
perl, perl6, raku
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
perl | Fixed | Fixed | Fixed | Not affected | Not affected |
perl6 | Not in release | Not in release | Needs evaluation | Needs evaluation | Ignored |
raku | Needs evaluation | Not in release | Not in release | Ignored | Ignored |
CVE-2022-48522
Low priorityIn Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
1 affected package
perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
perl | — | Fixed | Not affected | Not affected | Not affected |
CVE-2023-31486
Medium priorityHTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
2 affected packages
libhttp-tiny-perl, perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libhttp-tiny-perl | — | Ignored | Ignored | Ignored | Ignored |
perl | — | Ignored | Ignored | Ignored | Ignored |
CVE-2023-31485
Medium priorityGitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
1 affected package
libgitlab-api-v4-perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgitlab-api-v4-perl | Not affected | Ignored | Ignored | Ignored | Ignored |
CVE-2023-31484
Medium priorityCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
1 affected package
perl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
perl | — | Fixed | Fixed | Fixed | Fixed |