Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

rocky логотип

RLSA-2026:30851

около 1 месяца назад

Important: perl:5.32 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30851

около 1 месяца назад

ELSA-2026-30851: perl:5.32 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-42496

2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-42496

2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-42496

2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-42496

около 2 месяцев назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-42496

2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code ...

CVSS3: 7.3
EPSS: Низкий
rocky логотип

RLSA-2026:30857

27 дней назад

Important: perl-Archive-Tar security update

EPSS: Низкий
rocky логотип

RLSA-2026:30856

около 1 месяца назад

Important: perl-Archive-Tar security update

EPSS: Низкий
github логотип

GHSA-8p37-q9qq-hgx8

2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-30857

16 дней назад

ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30856

около 1 месяца назад

ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30852

около 1 месяца назад

ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:30860

27 дней назад

Important: perl-IO-Compress security update

EPSS: Низкий
rocky логотип

RLSA-2026:30859

около 1 месяца назад

Important: perl-IO-Compress security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:30851

Important: perl:5.32 security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-30851

ELSA-2026-30851: perl:5.32 security update (IMPORTANT)

около 1 месяца назад
ubuntu логотип
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 8.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...

CVSS3: 9.1
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob

CVSS3: 7.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code ...

CVSS3: 7.3
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:30857

Important: perl-Archive-Tar security update

0%
Низкий
27 дней назад
rocky логотип
RLSA-2026:30856

Important: perl-Archive-Tar security update

0%
Низкий
около 1 месяца назад
github логотип
GHSA-8p37-q9qq-hgx8

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-30857

ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT)

16 дней назад
oracle-oval логотип
ELSA-2026-30856

ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-30852

ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:30860

Important: perl-IO-Compress security update

0%
Низкий
27 дней назад
rocky логотип
RLSA-2026:30859

Important: perl-IO-Compress security update

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу