Search CVE reports


Toggle filters

231 – 240 of 243 results


CVE-2006-0898

Medium priority
Fixed

Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such...

1 affected package

libcrypt-cbc-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-cbc-perl
Show less packages

CVE-2005-4536

Medium priority
Fixed

Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on...

1 affected package

libmail-audit-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmail-audit-perl
Show less packages

CVE-2005-3962

Medium priority
Fixed

Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values,...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2005-0106

Medium priority
Fixed

SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

1 affected package

libnet-ssleay-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-ssleay-perl
Show less packages

CVE-2005-1349

Medium priority
Not affected

Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.

1 affected package

libconvert-uulib-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libconvert-uulib-perl
Show less packages

CVE-2005-1127

Medium priority
Fixed

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of...

2 affected packages

libnet-server-perl, postgrey

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-server-perl
postgrey
Show less packages

CVE-2005-0448

Medium priority
Fixed

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2005-0155

Medium priority
Fixed

The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages

CVE-2005-0077

Medium priority
Fixed

The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.

1 affected package

libdbi-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libdbi-perl
Show less packages

CVE-2004-0976

Medium priority
Fixed

Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl
Show less packages