Perl 5.35.6

CPE Details

Perl 5.35.6
5.35.6
2023-02-13
22h15 +00:00
2023-02-22
18h27 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:perl:perl:5.35.6:*:*:*:*:*:*:*

Informations

Vendor

perl

Product

perl

Version

5.35.6

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-47100 2023-12-01
23h00 +00:00
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
9.8
Critical
CVE-2023-31486 2023-04-28
00h00 +00:00
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
8.1
High
CVE-2023-31484 2023-04-27
22h00 +00:00
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
8.1
High
CVE-2016-1246 2016-10-05
14h00 +00:00
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
7.5
High
CVE-2011-3599 2011-10-10
08h00 +00:00
The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack.
5.8
CVE-2011-2201 2011-09-14
15h00 +00:00
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
4.3
CVE-2010-1168 2010-06-21
14h00 +00:00
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
7.5
CVE-2009-1884 2009-08-19
15h00 +00:00
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
4.3
CVE-2009-0663 2009-04-30
18h00 +00:00
Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.
7.5