CVE-2026-88816
- EPSS 0.21%
- Veröffentlicht 28.09.2026 16:04:40
- Zuletzt bearbeitet 30.09.2026 20:17:35
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has b...
CVE-2026-88815
- EPSS 0.21%
- Veröffentlicht 28.09.2026 16:04:22
- Zuletzt bearbeitet 30.09.2026 20:17:35
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An int...
CVE-2026-78030
- EPSS 0.73%
- Veröffentlicht 19.09.2026 10:45:10
- Zuletzt bearbeitet 22.09.2026 19:07:00
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require...
CVE-2026-73194
- EPSS 0.2%
- Veröffentlicht 15.08.2026 12:09:22
- Zuletzt bearbeitet 28.08.2026 15:42:20
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. T...
CVE-2026-14740
- EPSS 0.39%
- Veröffentlicht 07.07.2026 22:05:45
- Zuletzt bearbeitet 10.07.2026 14:40:21
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during norma...
CVE-2026-14739
- EPSS 0.39%
- Veröffentlicht 07.07.2026 22:05:18
- Zuletzt bearbeitet 10.07.2026 14:41:16
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1...
CVE-2026-14380
- EPSS 0.48%
- Veröffentlicht 07.07.2026 22:04:49
- Zuletzt bearbeitet 31.08.2026 10:16:48
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a ...
CVE-2026-9698
- EPSS 0.46%
- Veröffentlicht 09.06.2026 07:22:25
- Zuletzt bearbeitet 03.09.2026 13:06:25
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence ...
CVE-2026-10879
- EPSS 0.49%
- Veröffentlicht 05.06.2026 14:30:58
- Zuletzt bearbeitet 10.06.2026 15:02:24
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per bind...
CVE-2019-20919
- EPSS 0.51%
- Veröffentlicht 17.09.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:39:41
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.