Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 7.0% | — | Perl | 28/9/2017 | 17/6/2026 | Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable. | |
| Modificada | Crítica (9.1) | 5.9% | — | Perl | 19/9/2017 | 17/6/2026 | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape. | |
| Modificada | Alta (7.5) | 6.2% | — | Perl | 19/9/2017 | 17/6/2026 | Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier. | |
| Modificada | Media (5.5) | 0.32% | — | Perltidy Project Perltidy | 17/5/2017 | 17/6/2026 | perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating… | |
| Modificada | Crítica (9.8) | 4.6% | — | Perl | 7/2/2017 | 17/6/2026 | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument. | |
| Modificada | Alta (7.1) | 1.2% | — | Image-info Project Image-info FOR Perl | 22/12/2016 | 17/6/2026 | perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure. | |
| Modificada | Crítica (9.1) | 3.6% | — | Xmltwig Xml-twig FOR Perl | 22/12/2016 | 17/6/2026 | perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting. | |
| Modificada | Alta (7.8) | 0.79% | — | PerlFedoraproject FedoraDebian LinuxOracle Solaris+1 | 2/8/2016 | 17/6/2026 | The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory. | |
| Modificada | Alta (7.8) | 0.78% | — | Debian LinuxFedoraproject FedoraPerlOpensuse Leap+1 | 2/8/2016 | 17/6/2026 | (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11)… | |
| Modificada | Alta (7.5) | 2.6% | — | Fedoraproject FedoraPerl | 25/5/2016 | 17/6/2026 | The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80." | |
| Modificada | Alta (7.5) | 9.1% | — | PerlDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Configuration Manager+6 | 8/4/2016 | 17/6/2026 | Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. | |
| Modificada | Alta (7.3) | 3.1% | — | Canonical Ubuntu LinuxPerl PathtoolsDebian Linux | 13/1/2016 | 17/6/2026 | The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string. | |
| Modificada | Alta (7.5) | 3.5% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pcre Perl Compatible Regular Expression LibraryPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client. | |
| Modificada | Alta (7.5) | 3.6% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a… | |
| Modificada | Crítica (9.8) | 4.7% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 6.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Alta (7.3) | 3.6% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 6.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraOracle LinuxPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by… | |
| Modificada | Alta (7.5) | 5.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object… | |
| Modificada | Alta (7.5) | 3.4% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Crítica (9.8) | 6.1% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Media (6.4) | 4.0% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially… |