Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

github логотип

GHSA-q6wx-vhvq-x7h6

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2026-48962

2 месяца назад

IO::Compress versions before 2.220 for Perl can execute arbitrary code ...

CVSS3: 7.3
EPSS: Низкий
rocky логотип

RLSA-2026:30860

27 дней назад

Important: perl-IO-Compress security update

EPSS: Низкий
rocky логотип

RLSA-2026:30859

около 1 месяца назад

Important: perl-IO-Compress security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30860

16 дней назад

ELSA-2026-30860: perl-IO-Compress security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30859

около 1 месяца назад

ELSA-2026-30859: perl-IO-Compress security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30858

около 1 месяца назад

ELSA-2026-30858: perl-IO-Compress security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30843

11 дней назад

ELSA-2026-30843: perl-IO-Compress security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21177-1

около 1 месяца назад

Security update for perl-IO-Compress

EPSS: Низкий
rocky логотип

RLSA-2026:30851

около 1 месяца назад

Important: perl:5.32 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30851

около 1 месяца назад

ELSA-2026-30851: perl:5.32 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q6wx-vhvq-x7h6

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.

CVSS3: 7.3
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob

CVSS3: 7.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code ...

CVSS3: 7.3
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:30860

Important: perl-IO-Compress security update

0%
Низкий
27 дней назад
rocky логотип
RLSA-2026:30859

Important: perl-IO-Compress security update

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-30860

ELSA-2026-30860: perl-IO-Compress security update (IMPORTANT)

16 дней назад
oracle-oval логотип
ELSA-2026-30859

ELSA-2026-30859: perl-IO-Compress security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-30858

ELSA-2026-30858: perl-IO-Compress security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-30843

ELSA-2026-30843: perl-IO-Compress security update (IMPORTANT)

11 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21177-1

Security update for perl-IO-Compress

около 1 месяца назад
rocky логотип
RLSA-2026:30851

Important: perl:5.32 security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-30851

ELSA-2026-30851: perl:5.32 security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу