Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 94 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)94▼ 417 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.3% | — | Andy Armstrong Cgi.pm | 21/11/2012 | 16/6/2026 | CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm. | |
| Modificada | Media (4.3) | 2.6% | — | Andy Armstrong Cgi.pm | 6/12/2010 | 16/6/2026 | Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761. | |
| Modificada | Media (4.3) | 2.1% | — | Andy Armstrong Cgi.pmAndy Armstrong Cgi-simple | 6/12/2010 | 16/6/2026 | CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a… | |
| Modificada | Media (4.3) | 2.7% | — | Andy Armstrong Cgi.pmAndy Armstrong Cgi-simple | 6/12/2010 | 16/6/2026 | The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input… | |
| Modificada | Media (4.3) | 4.4% | — | Cgi.pmOpenpkgDebian Linux | 27/8/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter. |