Larry Wall's vulnerability profile centers on Perl, a widely deployed scripting language that sits in the infrastructure of countless systems and applications. The vendor's disclosures cluster around memory-handling and bounds-checking weaknesses, reflecting the low-level parsing and buffer-management demands inherent to language interpreters, and have an elevated tendency toward public exploit availability. Defenders should track this vendor's releases closely given Perl's ubiquity in legacy and production infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Larry Wall over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2286HIGH Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, | Dec 31, 2004 | 7.5 | 31 | NO | YES |
CVE-2004-0377HIGH Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands vi | May 4, 2004 | 10.0 | 27 | NO | NO |
CVE-2000-0703HIGH suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the | Oct 20, 2000 | 7.2 | 27 | NO | YES |
CVE-1999-0034HIGH Buffer overflow in suidperl (sperl), Perl 4.x and 5.x. | May 29, 1997 | 7.2 | 27 | NO | YES |
CVE-2007-5116HIGH Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching | Nov 7, 2007 | 7.5 | 23 | NO | NO |
CVE-2005-0155MEDIUM The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable. | May 2, 2005 | 4.6 | 21 | NO | YES |
CVE-2005-4278HIGH Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage | Dec 16, 2005 | 7.2 | 20 | NO | NO |
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG var | Feb 7, 2005 | 2.1 | 17 | NO | YES |
CVE-2003-0900MEDIUM Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers. | Dec 31, 2003 | 5.0 | 15 | NO | NO |
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files | Dec 21, 2004 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Larry Wall.
Media articles that mention a CVE ID that affects a product developed by Larry Wall — matched by CVE ID, not by vendor name.