Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Activestate

First CVE: Dec 6, 2001Active for: 25 yearsTotal CVEs: 9

Activestate maintains a focused portfolio of language-runtime and scripting-platform distributions—ActivePerl, ActivePython, and ActiveTcl—that serve developers relying on curated, pre-packaged interpreters. Although the vendor's vulnerability footprint is modest in volume, its disclosed issues frequently acquire public exploit code, reflecting the appeal of language runtimes as attack vectors for supply-chain and interpreter-level compromise. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Activestate over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2001
24 years ago
Most Recent CVE
Oct 11, 2012
5,034 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-0815HIGH
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in
Dec 6, 20017.535NOYES
CVE-2012-5379HIGH
Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\ directory, might allow local users to gain privil
Oct 11, 20127.332NOYES
CVE-2004-2286HIGH
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier,
Dec 31, 20047.531NOYES
CVE-2012-5377MEDIUM
Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows local users to gain privilege
Oct 11, 20126.030NOYES
CVE-2012-5378MEDIUM
Untrusted search path vulnerability in the installation functionality in ActiveTcl 8.5.12, when installed in the top-level C:\ directory, allows local users to gain privileges via
Oct 11, 20126.028NOYES
CVE-2004-0377HIGH
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands vi
May 4, 200410.027NONO
CVE-2004-2022LOW
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arb
Dec 31, 20042.123NOYES
CVE-2002-0131MEDIUM
ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which al
Mar 25, 20025.016NONO
CVE-2006-2856MEDIUM
ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by cre
Jun 6, 20064.614NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
44%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None0 (0.0%)
Unknown8 (88.9%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (88.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
66.7% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Activestate.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Activestate — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Activestate's Products

View all 1 CNAs →