Search CVE reports


Toggle filters

1 – 10 of 262 results


CVE-2026-40199

Medium priority
Needs evaluation

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped...

1 affected package

libnet-cidr-lite-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-cidr-lite-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40198

Medium priority
Needs evaluation

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactly 8 hex groups. Inputs like...

1 affected package

libnet-cidr-lite-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnet-cidr-lite-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-14031

Medium priority
Not affected

Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a...

1 affected package

libsereal-encoder-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsereal-encoder-perl Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-14030

Medium priority
Not affected

Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a...

1 affected package

libsereal-encoder-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsereal-encoder-perl Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-4176

Medium priority
Needs evaluation

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life...

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2014-125112

Medium priority
Needs evaluation

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary...

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2006-10003

Medium priority

Some fixes available 3 of 6

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location...

1 affected package

libxml-parser-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml-parser-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2006-10002

Medium priority

Some fixes available 3 of 6

XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input...

1 affected package

libxml-parser-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml-parser-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-4177

Medium priority
Needs evaluation

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial...

1 affected package

libyaml-syck-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyaml-syck-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3381

Medium priority
Needs evaluation

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which...

2 affected packages

libcompress-raw-zlib-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcompress-raw-zlib-perl Not affected Not affected Needs evaluation Needs evaluation
perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages