Search CVE reports


Toggle filters

1 – 10 of 234 results


CVE-2025-40924

Medium priority
Needs evaluation

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and...

1 affected package

libcatalyst-plugin-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40923

Medium priority
Needs evaluation

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come...

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40918

Medium priority
Needs evaluation

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will...

1 affected package

libauthen-sasl-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libauthen-sasl-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40914

Medium priority
Needs evaluation

Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

1 affected package

libcryptx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcryptx-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40912

Medium priority
Needs evaluation

CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.

1 affected package

libcryptx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcryptx-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-40911

Medium priority
Needs evaluation

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are...

1 affected package

libnet-cidr-set-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-cidr-set-perl Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40909

Medium priority

Some fixes available 3 of 8

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-40908

Medium priority

Some fixes available 2 of 6

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

1 affected package

libyaml-libyaml-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyaml-libyaml-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-40907

Medium priority
Fixed

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based...

1 affected package

libfcgi-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfcgi-perl Not affected Not affected Fixed Fixed
Show less packages

CVE-2025-40906

Medium priority
Needs evaluation

BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and...

1 affected package

libbson-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libbson-xs-perl Needs evaluation Needs evaluation Needs evaluation
Show less packages