Search CVE reports


Toggle filters

101 – 110 of 251 results


CVE-2019-1010161

Medium priority
Not affected

perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is:...

1 affected package

libcrypt-jwt-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-jwt-perl Not in release
Show less packages

CVE-2019-1010263

Medium priority
Needs evaluation

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector...

1 affected package

libcrypt-jwt-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-jwt-perl Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2018-18898

Medium priority

Some fixes available 5 of 6

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

1 affected package

libemail-address-list-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-list-perl Fixed Fixed
Show less packages

CVE-2018-18314

Medium priority
Fixed

Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18313

Medium priority
Fixed

Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18312

Medium priority
Fixed

Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2018-18311

Medium priority
Fixed

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed
Show less packages

CVE-2011-2767

Medium priority
Fixed

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the...

1 affected package

libapache2-mod-perl2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-perl2 Fixed
Show less packages

CVE-2018-10860

Medium priority
Fixed

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive...

1 affected package

libarchive-zip-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive-zip-perl Fixed
Show less packages

CVE-2018-12558

Low priority
Vulnerable

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30...

1 affected package

libemail-address-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libemail-address-perl Not affected Not affected Not affected Vulnerable
Show less packages