Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14740

Опубликовано: 07 июл. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.

The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*
Версия до 1.650 (исключая)

EPSS

Процентиль: 31%
0.00387
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

CVSS3: 5
redhat
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

CVSS3: 9.1
msrc
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

CVSS3: 9.1
debian
около 1 месяца назад

DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...

suse-cvrf
около 1 месяца назад

Security update for perl-DBI

EPSS

Процентиль: 31%
0.00387
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125