CVE-2019-25777
- EPSS 0.22%
- Veröffentlicht 05.10.2026 06:50:17
- Zuletzt bearbeitet 06.10.2026 17:17:09
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing r...
CVE-2017-20285
- EPSS 0.18%
- Veröffentlicht 05.10.2026 06:49:17
- Zuletzt bearbeitet 06.10.2026 17:17:08
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it go...
CVE-2026-87082
- EPSS 0.4%
- Veröffentlicht 22.09.2026 07:25:37
- Zuletzt bearbeitet 22.09.2026 19:07:00
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed ...
CVE-2026-15743
- EPSS -
- Veröffentlicht 20.08.2026 18:15:26
- Zuletzt bearbeitet 28.08.2026 16:17:07
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content m...
CVE-2026-73193
- EPSS 0.2%
- Veröffentlicht 15.08.2026 12:09:03
- Zuletzt bearbeitet 28.08.2026 15:42:20
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seve...
CVE-2026-19487
- EPSS 0.43%
- Veröffentlicht 13.08.2026 15:51:04
- Zuletzt bearbeitet 28.08.2026 15:42:20
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match...
CVE-2026-13221
- EPSS 0.43%
- Veröffentlicht 13.07.2026 15:40:11
- Zuletzt bearbeitet 08.09.2026 22:17:37
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk....
CVE-2026-57432
- EPSS 0.21%
- Veröffentlicht 13.07.2026 15:38:20
- Zuletzt bearbeitet 08.09.2026 22:18:30
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat...
CVE-2026-8376
- EPSS 0.44%
- Veröffentlicht 25.05.2026 23:53:27
- Zuletzt bearbeitet 08.09.2026 22:19:18
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the ...
CVE-2026-4176
- EPSS 0.68%
- Veröffentlicht 29.03.2026 20:50:51
- Zuletzt bearbeitet 22.04.2026 17:31:45
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerab...