Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Perl Convert Uulib | 2/5/2005 | 16/6/2026 | Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation. | |
| Modificada | Baja (1.2) | 0.38% | — | Larry Wall Perl | 2/5/2005 | 16/6/2026 | Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Logicnow Perldesk | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter. | |
| Modificada | Media (5) | 1.9% | — | Arpanet Perlshop | 2/5/2005 | 16/6/2026 | perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request. | |
| Modificada | Baja (2.1) | 0.43% | — | Larry Wall Perl | 9/2/2005 | 16/6/2026 | Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 1.3% | 💥 Exploit | Larry Wall PerlSGI PropackIBM AIXRedhat Enterprise Linux+5 | 7/2/2005 | 16/6/2026 | Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Activestate ActiveperlLarry Wall Perl | 31/12/2004 | 16/6/2026 | Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow. | |
| Modificada | Baja (2.1) | 1.7% | 💥 Exploit | Activestate Activeperl | 31/12/2004 | 16/6/2026 | ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug… | |
| Modificada | Baja (2.6) | 0.40% | — | Larry Wall Perl | 21/12/2004 | 16/6/2026 | Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Logicnow Perldesk | 13/9/2004 | 16/6/2026 | Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message… | |
| Modificada | Media (5) | 1.5% | — | Logicnow Perldesk | 12/9/2004 | 16/6/2026 | pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message. | |
| Modificada | Baja (2.1) | 0.36% | — | SuidperlDebian Linux | 4/5/2004 | 16/6/2026 | Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions. | |
| Modificada | Alta (10) | 6.8% | — | Activestate ActiveperlLarry Wall Perl | 4/5/2004 | 16/6/2026 | Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character. | |
| Modificada | Media (5) | 1.4% | — | Larry Wall Perl | 31/12/2003 | 16/6/2026 | Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers. | |
| Modificada | Media (5) | 1.9% | — | Perl CGI Lite | 31/12/2003 | 16/6/2026 | The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary… | |
| Modificada | Media (5) | 2.0% | — | Perl-httpd | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument. | |
| Modificada | Alta (7.5) | 2.1% | — | Perlbot | 31/12/2002 | 16/6/2026 | Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm. | |
| Modificada | Alta (7.5) | 2.1% | — | Perlbot | 31/12/2002 | 16/6/2026 | Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address. | |
| Modificada | Alta (7.5) | 3.6% | — | Perl-mailtools | 12/11/2002 | 16/6/2026 | The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Activestate Activeperl | 6/12/2001 | 16/6/2026 | Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Cosmicperl Directory PRO | 18/10/2001 | 16/6/2026 | Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter. | |
| Modificada | Alta (7.5) | 2.8% | — | Ralf S. Engelschall Eperl | 18/10/2001 | 16/6/2026 | The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Acme Labs Perlcal | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Spencer Christensen Perl WEB Server | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 2.4% | — | Ralf S. Engelschall EperlDebian LinuxMandrakesoft Mandrake LinuxSuse Linux | 27/6/2001 | 16/6/2026 | Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. |