Search CVE reports


Toggle filters

1 – 10 of 245 results


CVE-2026-0943

Medium priority
Needs evaluation

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball,...

1 affected package

libharfbuzz-shaper-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libharfbuzz-shaper-perl Not in release Not in release
Show less packages

CVE-2013-10031

Medium priority
Needs evaluation

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-11683

Medium priority
Fixed

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent...

1 affected package

libyaml-syck-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyaml-syck-perl Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-40929

Medium priority

Some fixes available 4 of 7

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

1 affected package

libcpanel-json-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcpanel-json-xs-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-40928

Medium priority

Some fixes available 4 of 8

JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

1 affected package

libjson-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjson-xs-perl Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-40927

Medium priority
Needs evaluation

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for...

1 affected package

libcgi-simple-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcgi-simple-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40920

Medium priority
Needs evaluation

Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID...

1 affected package

libcatalyst-authentication-credential-http-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-authentication-credential-http-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40924

Medium priority
Needs evaluation

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and...

1 affected package

libcatalyst-plugin-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40918

Low priority
Needs evaluation

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will...

1 affected package

libauthen-sasl-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libauthen-sasl-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-40923

Medium priority
Needs evaluation

Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come...

1 affected package

libplack-middleware-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libplack-middleware-session-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages