Perl
Perl DBI: vulnerabilidades y CVE
Perl DBI tiene 18 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses13
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88816 | Alta (7.5) | 0.62% | — | 28 sept 2026 | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it… |
| CVE-2026-88815 | Media (6.2) | 0.18% | — | 28 sept 2026 | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without… |
| CVE-2026-78030 | Crítica (9.8) | 0.42% | — | 19 sept 2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the… |
| CVE-2026-73194 | Crítica (9.1) | 0.49% | — | 15 ago 2026 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the… |
| CVE-2026-73193 | Crítica (9.8) | 0.65% | — | 15 ago 2026 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with… |
| CVE-2026-19546 | Alta (8.8) | 0.35% | — | 11 ago 2026 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original… |
| CVE-2026-60082 | Crítica (9.1) | 0.65% | — | 14 jul 2026 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a… |
| CVE-2026-15043 | Crítica (9.8) | 0.39% | — | 14 jul 2026 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the… |
| CVE-2026-14740 | Crítica (9.1) | 0.39% | — | 7 jul 2026 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the… |
| CVE-2026-14739 | Crítica (9.8) | 0.41% | — | 7 jul 2026 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately… |
| CVE-2026-14380 | Alta (8.8) | 0.50% | — | 7 jul 2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and… |
| CVE-2026-9698 | Crítica (9.8) | 0.82% | — | 9 jun 2026 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.… |
| CVE-2026-10879 | Crítica (9.8) | 0.48% | — | 5 jun 2026 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only… |
| CVE-2019-20919 | Media (4.7) | 0.51% | — | 17 sept 2020 | An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer… |
| CVE-2014-10402 | Media (6.1) | 0.48% | — | 16 sept 2020 | An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this… |
| CVE-2014-10401 | Media (6.1) | 0.44% | — | 11 sept 2020 | An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute. |
| CVE-2013-7491 | Media (5.3) | 2.7% | — | 11 sept 2020 | An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated. |
| CVE-2013-7490 | Media (5.3) | 2.7% | — | 11 sept 2020 | An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.