Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

355 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)7.0%—Perl28/9/201717/6/2026
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.
ModificadaCrítica (9.1)5.9%—Perl19/9/201717/6/2026
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
ModificadaAlta (7.5)6.2%—Perl19/9/201717/6/2026
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
ModificadaMedia (5.5)0.32%—Perltidy Project Perltidy17/5/201717/6/2026
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating…
ModificadaCrítica (9.8)4.6%—Perl7/2/201717/6/2026
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.
ModificadaAlta (7.1)1.2%—Image-info Project Image-info FOR Perl22/12/201617/6/2026
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
ModificadaCrítica (9.1)3.6%—Xmltwig Xml-twig FOR Perl22/12/201617/6/2026
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.
ModificadaAlta (7.8)0.79%—PerlFedoraproject FedoraDebian LinuxOracle Solaris+12/8/201617/6/2026
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
ModificadaAlta (7.8)0.78%—Debian LinuxFedoraproject FedoraPerlOpensuse Leap+12/8/201617/6/2026
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11)…
ModificadaAlta (7.5)2.6%—Fedoraproject FedoraPerl25/5/201617/6/2026
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."
ModificadaAlta (7.5)9.1%—PerlDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Configuration Manager+68/4/201617/6/2026
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
ModificadaAlta (7.3)3.1%—Canonical Ubuntu LinuxPerl PathtoolsDebian Linux13/1/201617/6/2026
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
ModificadaAlta (7.5)3.5%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392.
ModificadaCrítica (9.8)4.8%—Pcre Perl Compatible Regular Expression LibraryPHP2/12/201517/6/2026
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaAlta (7.5)4.4%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP2/12/201517/6/2026
pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.
ModificadaAlta (7.5)3.6%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a…
ModificadaCrítica (9.8)4.7%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP2/12/201517/6/2026
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaCrítica (9.8)3.9%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP2/12/201517/6/2026
PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaAlta (7.5)6.6%—Oracle LinuxPcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp…
ModificadaAlta (7.3)3.6%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP2/12/201517/6/2026
PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaCrítica (9.8)6.9%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraOracle LinuxPHP2/12/201517/6/2026
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by…
ModificadaAlta (7.5)5.6%—Oracle LinuxPcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object…
ModificadaAlta (7.5)3.4%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp…
ModificadaCrítica (9.8)6.1%—Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP2/12/201517/6/2026
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaMedia (6.4)4.0%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially…