Search CVE reports


Toggle filters

1 – 10 of 241 results


CVE-2025-40928

Medium priority
Needs evaluation

JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

1 affected package

libjson-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjson-xs-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40927

Medium priority
Needs evaluation

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for...

1 affected package

libcgi-simple-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcgi-simple-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40920

Medium priority
Needs evaluation

Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID...

1 affected package

libcatalyst-authentication-credential-http-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-authentication-credential-http-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40924

Medium priority
Needs evaluation

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and...

1 affected package

libcatalyst-plugin-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40918

Low priority
Needs evaluation

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will...

1 affected package

libauthen-sasl-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libauthen-sasl-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40923

Medium priority
Needs evaluation

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come...

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40912

Medium priority
Needs evaluation

CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.

1 affected package

libcryptx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcryptx-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-40914

Medium priority
Needs evaluation

Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

1 affected package

libcryptx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcryptx-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2011-10007

Medium priority

Some fixes available 4 of 7

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to...

1 affected package

libfile-find-rule-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfile-find-rule-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-40908

Medium priority

Some fixes available 2 of 6

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

1 affected package

libyaml-libyaml-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyaml-libyaml-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages