Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.44% | — | Perl DBI | 11/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute. | |
| Modificada | Media (5.3) | 2.7% | — | Perl DBI | 11/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated. | |
| Modificada | Media (5.3) | 2.7% | — | Perl DBICanonical Ubuntu Linux | 11/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption. | |
| Modificada | Alta (7.5) | 1.1% | — | P5-crypt-perl Project P5-crypt-perl | 10/8/2020 | 17/6/2026 | ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm. | |
| Modificada | Alta (8.8) | 0.71% | — | P5-crypt-perl Project P5-crypt-perl | 7/6/2020 | 17/6/2026 | Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v1). This could conceivably have a security-relevant impact if an attacker wishes to use public r… | |
| Modificada | Alta (7.5) | 6.0% | — | PerlNetapp Oncommand Workflow AutomationNetapp Snap Creator FrameworkFedoraproject Fedora+12 | 5/6/2020 | 17/6/2026 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. | |
| Modificada | Alta (8.6) | 4.9% | — | PerlFedoraproject FedoraOpensuse LeapNetapp Oncommand Workflow Automation+13 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. | |
| Modificada | Alta (8.2) | 11% | — | PerlFedoraproject FedoraOpensuse LeapOracle Communications Billing AND Revenue Management+11 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. | |
| Modificada | Crítica (9.8) | 1.3% | — | Perlspeak Project Perlspeak | 18/3/2020 | 17/6/2026 | PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open. | |
| Modificada | Crítica (9.8) | 1.7% | — | Libpoe-component-irc-perl Project Libpoe-component-irc-perlDebian LinuxFedoraproject Fedora | 12/11/2019 | 16/6/2026 | libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server. | |
| Modificada | Crítica (9.8) | 1.1% | — | Perl-crypt-jwt Project Perl-crypt-jwt | 25/7/2019 | 17/6/2026 | perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(crafting user-controlled input to bypass authentication). The fixed version is: 0.023. | |
| Modificada | Crítica (9.8) | 1.3% | — | Perl Crypt\ \ | 17/7/2019 | 17/6/2026 | Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: network connectivity. The fixed version is: after commit… | |
| Modificada | Crítica (9.8) | 6.1% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+4 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.1) | 9.5% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+5 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. | |
| Modificada | Crítica (9.8) | 12% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+14 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.8) | 13% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+4 | 5/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.8) | 8.9% | — | Apache MOD PerlDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 26/8/2018 | 16/6/2026 | mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users… | |
| Modificada | Alta (7.5) | 43% | — | Canonical Ubuntu LinuxDebian LinuxPerl-archive-zip Project Perl-archive-zip | 29/6/2018 | 17/6/2026 | perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context… | |
| Modificada | Alta (7.5) | 7.3% | — | Canonical Ubuntu LinuxDebian LinuxPerlArchive\ \+5 | 7/6/2018 | 17/6/2026 | In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name. | |
| Modificada | Alta (7.5) | 0.82% | — | Hyperledger Iroha | 1/6/2018 | 17/6/2026 | Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate… | |
| Modificada | Crítica (9.8) | 11% | — | Debian LinuxPerlCanonical Ubuntu Linux | 17/4/2018 | 17/6/2026 | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count. | |
| Modificada | Alta (7.5) | 3.9% | — | Debian LinuxPerlCanonical Ubuntu LinuxRedhat Enterprise Linux Server+1 | 17/4/2018 | 17/6/2026 | An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure. | |
| Modificada | Crítica (9.8) | 6.5% | — | Debian LinuxPerlCanonical Ubuntu LinuxRedhat Enterprise Linux Server+1 | 17/4/2018 | 17/6/2026 | An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Alta (7.1) | 0.35% | — | Perltidy Project Perltidy | 17/10/2017 | 17/6/2026 | The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function. |