Activestate maintains a focused portfolio of language-runtime and scripting-platform distributions—ActivePerl, ActivePython, and ActiveTcl—that serve developers relying on curated, pre-packaged interpreters. Although the vendor's vulnerability footprint is modest in volume, its disclosed issues frequently acquire public exploit code, reflecting the appeal of language runtimes as attack vectors for supply-chain and interpreter-level compromise. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activestate over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0815HIGH Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in | Dec 6, 2001 | 7.5 | 35 | NO | YES |
CVE-2012-5379HIGH Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\ directory, might allow local users to gain privil | Oct 11, 2012 | 7.3 | 32 | NO | YES |
CVE-2004-2286HIGH Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, | Dec 31, 2004 | 7.5 | 31 | NO | YES |
CVE-2012-5377MEDIUM Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows local users to gain privilege | Oct 11, 2012 | 6.0 | 30 | NO | YES |
CVE-2012-5378MEDIUM Untrusted search path vulnerability in the installation functionality in ActiveTcl 8.5.12, when installed in the top-level C:\ directory, allows local users to gain privileges via | Oct 11, 2012 | 6.0 | 28 | NO | YES |
CVE-2004-0377HIGH Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands vi | May 4, 2004 | 10.0 | 27 | NO | NO |
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arb | Dec 31, 2004 | 2.1 | 23 | NO | YES |
CVE-2002-0131MEDIUM ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which al | Mar 25, 2002 | 5.0 | 16 | NO | NO |
CVE-2006-2856MEDIUM ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by cre | Jun 6, 2006 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activestate.
Media articles that mention a CVE ID that affects a product developed by Activestate — matched by CVE ID, not by vendor name.