Search CVE reports


Toggle filters

1 – 10 of 251 results


CVE-2025-40932

Medium priority
Needs evaluation

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 returns a MD5 hash seeded with the...

1 affected package

libapache-sessionx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-sessionx-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-4456

Medium priority
Needs evaluation

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be...

1 affected package

libnet-cidr-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-cidr-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3102

Medium priority
Not affected

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the...

1 affected package

libimage-exiftool-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libimage-exiftool-perl Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-2597

Medium priority
Needs evaluation

[Disallow requesting strings with negative lengths]

1 affected package

libcrypt-sysrandom-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-sysrandom-xs-perl Not in release Not in release
Show less packages

CVE-2026-2474

Medium priority
Needs evaluation

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative...

1 affected package

libcrypt-urandom-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-urandom-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40905

Medium priority
Needs evaluation

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

1 affected package

libwww-oauth-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libwww-oauth-perl Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0943

Medium priority
Needs evaluation

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball,...

1 affected package

libharfbuzz-shaper-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libharfbuzz-shaper-perl Not in release Not in release
Show less packages

CVE-2013-10031

Medium priority
Needs evaluation

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-11683

Medium priority
Fixed

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent...

1 affected package

libyaml-syck-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyaml-syck-perl Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-40929

Medium priority

Some fixes available 4 of 7

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

1 affected package

libcpanel-json-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcpanel-json-xs-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages