Activeperl
Vendor:
First CVE: Dec 6, 2001 · Active for 24 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Activeperl over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2001
24 years ago
Most Recent CVE
Oct 11, 2012
5,035 days ago
CVE Severity & Scoring
Activeperl6 CVEs
17%
33%
50%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0815HIGH Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in | Dec 6, 2001 | 7.5 | 35 | NO | YES |
CVE-2004-2286HIGH Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, | Dec 31, 2004 | 7.5 | 31 | NO | YES |
CVE-2012-5377MEDIUM Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows local users to gain privilege | Oct 11, 2012 | 6.0 | 30 | NO | YES |
CVE-2004-0377HIGH Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands vi | May 4, 2004 | 10.0 | 27 | NO | NO |
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arb | Dec 31, 2004 | 2.1 | 23 | NO | YES |
CVE-2006-2856MEDIUM ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by cre | Jun 6, 2006 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
66.7% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Activeperl
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.8.8.817 | 1 | 4.6 | 0.4% | 0 | 0 |
| 5.8.3 | 1 | 7.5 | 8.0% | 0 | 1 |
| 5.8.1 | 1 | 7.5 | 8.0% | 0 | 1 |
| 5.8 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.7.3 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.7.2 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.7.1 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.6.3 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.6.2 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.6.1.630 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.6.1 | 2 | 4.8 | 4.8% | 0 | 2 |
| 5.16.1.1601 | 1 | 6.0 | 1.3% | 0 | 1 |