Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

355 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)13%💥 ExploitPerl Convert Uulib2/5/200516/6/2026
Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.
ModificadaBaja (1.2)0.38%—Larry Wall Perl2/5/200516/6/2026
Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.
ModificadaAlta (7.5)2.4%💥 ExploitLogicnow Perldesk2/5/200516/6/2026
SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.
ModificadaMedia (5)1.9%—Arpanet Perlshop2/5/200516/6/2026
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.
ModificadaBaja (2.1)0.43%—Larry Wall Perl9/2/200516/6/2026
Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)1.3%💥 ExploitLarry Wall PerlSGI PropackIBM AIXRedhat Enterprise Linux+57/2/200516/6/2026
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
ModificadaAlta (7.5)8.0%💥 ExploitActivestate ActiveperlLarry Wall Perl31/12/200416/6/2026
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.
ModificadaBaja (2.1)1.7%💥 ExploitActivestate Activeperl31/12/200416/6/2026
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug…
ModificadaBaja (2.6)0.40%—Larry Wall Perl21/12/200416/6/2026
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.
ModificadaMedia (5)7.2%💥 ExploitLogicnow Perldesk13/9/200416/6/2026
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message…
ModificadaMedia (5)1.5%—Logicnow Perldesk12/9/200416/6/2026
pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.
ModificadaBaja (2.1)0.36%—SuidperlDebian Linux4/5/200416/6/2026
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.
ModificadaAlta (10)6.8%—Activestate ActiveperlLarry Wall Perl4/5/200416/6/2026
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.
ModificadaMedia (5)1.4%—Larry Wall Perl31/12/200316/6/2026
Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.
ModificadaMedia (5)1.9%—Perl CGI Lite31/12/200316/6/2026
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary…
ModificadaMedia (5)2.0%—Perl-httpd31/12/200216/6/2026
Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument.
ModificadaAlta (7.5)2.1%—Perlbot31/12/200216/6/2026
Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.
ModificadaAlta (7.5)2.1%—Perlbot31/12/200216/6/2026
Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.
ModificadaAlta (7.5)3.6%—Perl-mailtools12/11/200216/6/2026
The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.
ModificadaAlta (7.5)14%💥 ExploitActivestate Activeperl6/12/200116/6/2026
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension.
ModificadaMedia (5)7.5%💥 ExploitCosmicperl Directory PRO18/10/200116/6/2026
Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.
ModificadaAlta (7.5)2.8%—Ralf S. Engelschall Eperl18/10/200116/6/2026
The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.
ModificadaMedia (5)3.8%💥 ExploitAcme Labs Perlcal27/6/200116/6/2026
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
ModificadaMedia (5)3.6%💥 ExploitSpencer Christensen Perl WEB Server27/6/200116/6/2026
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaAlta (7.5)2.4%—Ralf S. Engelschall EperlDebian LinuxMandrakesoft Mandrake LinuxSuse Linux27/6/200116/6/2026
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
Orbitaley — Vulnerabilidades