Количество 49
Количество 49
RLSA-2026:62667
Important: perl-DBI security update
ELSA-2026-62667-0
ELSA-2026-62667-0: perl-DBI security update (IMPORTANT)
openSUSE-SU-2026:21029-1
Security update for perl-DBI
SUSE-SU-2026:2749-1
Security update for perl-DBI
RLSA-2026:38901
Important: perl-DBI:1.641 security update
RLSA-2026:38513
Important: perl-DBI security update
RLSA-2026:38512
Important: perl-DBI security update
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsin ...
RLSA-2026:52772
Important: perl-DBI:1.641 security update
RLSA-2026:49612
Important: perl-DBI security update
RLSA-2026:49514
Important: perl-DBI security update
ELSA-2026-52772
ELSA-2026-52772: perl-DBI:1.641 security update (IMPORTANT)
ELSA-2026-49612
ELSA-2026-49612: perl-DBI security update (IMPORTANT)
ELSA-2026-49514
ELSA-2026-49514: perl-DBI security update (IMPORTANT)
GHSA-c7xw-cj86-m724
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
CVE-2026-14380
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:62667 Important: perl-DBI security update | 12 дней назад | |||
ELSA-2026-62667-0 ELSA-2026-62667-0: perl-DBI security update (IMPORTANT) | 13 дней назад | |||
openSUSE-SU-2026:21029-1 Security update for perl-DBI | 3 месяца назад | |||
SUSE-SU-2026:2749-1 Security update for perl-DBI | 2 месяца назад | |||
RLSA-2026:38901 Important: perl-DBI:1.641 security update | 2 месяца назад | |||
RLSA-2026:38513 Important: perl-DBI security update | 2 месяца назад | |||
RLSA-2026:38512 Important: perl-DBI security update | 2 месяца назад | |||
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders | CVSS3: 8.6 | 0% Низкий | 3 месяца назад | |
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsin ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
RLSA-2026:52772 Important: perl-DBI:1.641 security update | около 1 месяца назад | |||
RLSA-2026:49612 Important: perl-DBI security update | около 1 месяца назад | |||
RLSA-2026:49514 Important: perl-DBI security update | около 1 месяца назад | |||
ELSA-2026-52772 ELSA-2026-52772: perl-DBI:1.641 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-49612 ELSA-2026-49612: perl-DBI security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-49514 ELSA-2026-49514: perl-DBI security update (IMPORTANT) | около 1 месяца назад | |||
GHSA-c7xw-cj86-m724 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host. | CVSS3: 8.8 | 1% Низкий | 2 месяца назад |
Уязвимостей на страницу