Perl
Vendor:
First CVE: May 29, 1997 · Active for 29 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Perl over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 1997
29 years ago
Most Recent CVE
Nov 7, 2007
6,836 days ago
CVE Severity & Scoring
Perl12 CVEs
33%
17%
50%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown12 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown12 (100.0%)
User Interaction
None0 (0.0%)
Unknown12 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (100.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2286HIGH Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, | Dec 31, 2004 | 7.5 | 31 | NO | YES |
CVE-2004-0377HIGH Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands vi | May 4, 2004 | 10.0 | 27 | NO | NO |
CVE-2000-0703HIGH suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the | Oct 20, 2000 | 7.2 | 27 | NO | YES |
CVE-1999-0034HIGH Buffer overflow in suidperl (sperl), Perl 4.x and 5.x. | May 29, 1997 | 7.2 | 27 | NO | YES |
CVE-2007-5116HIGH Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching | Nov 7, 2007 | 7.5 | 23 | NO | NO |
CVE-2005-0155MEDIUM The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable. | May 2, 2005 | 4.6 | 21 | NO | YES |
CVE-2005-4278HIGH Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage | Dec 16, 2005 | 7.2 | 20 | NO | NO |
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG var | Feb 7, 2005 | 2.1 | 17 | NO | YES |
CVE-2003-0900MEDIUM Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers. | Dec 31, 2003 | 5.0 | 15 | NO | NO |
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files | Dec 21, 2004 | 2.6 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
41.7% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Perl
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.8.6 | 1 | 7.5 | 4.8% | 0 | 0 |
| 5.8.4.5 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4.4 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4.3 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4.2.3 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4.2 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4.1 | 3 | 5.6 | 2.2% | 0 | 1 |
| 5.8.4 | 5 | 4.1 | 1.5% | 0 | 1 |
| 5.8.3 | 6 | 4.6 | 2.6% | 0 | 2 |
| 5.8.1 | 7 | 4.7 | 2.4% | 0 | 2 |
| 5.8.0 | 7 | 4.6 | 2.4% | 0 | 3 |
| 5.6.1 | 4 | 4.8 | 2.3% | 0 | 1 |
| 5.6 | 3 | 5.6 | 3.2% | 0 | 2 |
| 5.5.3 | 3 | 7.3 | 3.2% | 0 | 2 |
| 5.5 | 3 | 7.3 | 3.2% | 0 | 2 |
| 5.4.5 | 3 | 7.3 | 3.2% | 0 | 2 |
| 5.4 | 2 | 7.3 | 4.2% | 0 | 1 |
| 5.3 | 3 | 7.3 | 3.2% | 0 | 2 |