Perl Exploits

2,849 exploits tracked across all sources.

Sort: Activity Stars
CVE-2002-1862 EXPLOITDB perl VERIFIED
SmartMail Server 2.0 - Denial of Service via Early Connection Termination
SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.
by securma massine
CVE-2002-1945 EXPLOITDB perl VERIFIED
SmartMail Server 1.0 Beta 10 - Denial of Service via Long SMTP or POP3 Request
Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).
by securma massine
CVE-2002-1275 EXPLOITDB perl VERIFIED
html2ps 1.0 - Remote Code Execution
Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."
by Sebastian Krahmer
CVE-2002-1542 EXPLOITDB perl VERIFIED
SolarWinds TFTP server <5.0.55 - DoS
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
by D4rkGr3y
EIP-2026-103196 EXPLOITDB perl VERIFIED
PlanetDNS PlanetWeb 1.14 - Remote Buffer Overflow
by securma massine
CVE-2002-1222 EXPLOITDB perl VERIFIED
Cisco Catalyst <7.3 - Buffer Overflow
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.
by blackangels
CVE-2002-1179 EXPLOITDB perl VERIFIED
Microsoft Outlook Express <6.0 - RCE
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.
by Noam Rathaus
CVE-2002-1522 EXPLOITDB perl VERIFIED
PowerFTP 2.24 - Buffer Overflow via Long USER Argument
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.
by subj
CVE-2002-2154 EXPLOITDB perl VERIFIED
Monkey HTTP Daemon 0.1.4 - Path Traversal via Dot Dot Sequences
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.
by DownBload
CVE-2002-1489 EXPLOITDB perl VERIFIED
PlanetDNS PlanetWeb < 1.14 - Remote Code Execution via Long URL or Method Name
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.
by UkR-XblP
EIP-2026-114769 EXPLOITDB perl VERIFIED
HP Tru64 - NLSPATH Environment Variable Local Buffer Overflow (2)
by digitalmunition
CVE-2002-2360 EXPLOITDB perl VERIFIED
Webmin 0.21-0.99 - Unauthenticated Arbitrary File Read/Write and Remote Code Execution via RPC Module
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.
by Noam Rathaus
CVE-2002-1436 EXPLOITDB perl VERIFIED
Novell NetWare 5.1 and 6 - Remote Code Execution via Perl Web Handler
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
by Dan Elder
CVE-2002-1405 EXPLOITDB perl VERIFIED
Lynx <2.8.4 - CRLF Injection
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
by Ulf Harnhammar
CVE-2002-1452 EXPLOITDB perl VERIFIED
MyWebServer 1.0.2 - Remote Code Execution via Long searchTarget Parameter
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.
by D4rkGr3y
CVE-2002-0851 EXPLOITDB perl VERIFIED
isdn4linux - Local Privilege Escalation via Format String in ipppd Device Name Argument
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.
by TESO Security
CVE-2002-2351 EXPLOITDB perl VERIFIED
Qualcomm Eudora 5.1 - Path Traversal via Trailing Dot in Attachment Name
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
by Paul Szabo
CVE-2002-2351 EXPLOITDB perl VERIFIED
Qualcomm Eudora 5.1 - Path Traversal via Trailing Dot in Attachment Name
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
by Paul Szabo
CVE-2002-0833 EXPLOITDB perl VERIFIED
Qualcomm Eudora 5.0-J and 5.1.1 - Buffer Overflow via Multi-Part Message Boundary String
Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string.
by Kanatoko
CVE-2002-2174 EXPLOITDB perl VERIFIED
602Pro LAN SUITE 2002 - Denial of Service via Telnet Proxy Connection Flood
The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.
by Stan Bubrouski
EIP-2026-119224 EXPLOITDB perl VERIFIED
Trillian 0.x IRC Module - Remote Buffer Overflow
by John C. Hennessy
CVE-2002-0824 EXPLOITDB perl VERIFIED
Freebsd Point-to-point Protocol Daemon - Symlink Following
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
by Sebastian Krahmer
CVE-2002-0371 EXPLOITDB perl VERIFIED
Microsoft Internet Explorer 5.1-6.0 - Remote Code Execution via Gopher URL Buffer Overflow
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
CVE-2002-0637 EXPLOITDB perl VERIFIED
InterScan VirusWall 3.52 build 1462 - Auth Bypass
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.
by SecuriTeam
CVE-2002-1605 EXPLOITDB perl VERIFIED
HP Tru64 UNIX <5.1a-4.0f - Buffer Overflow
Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variable to (1) dxpause, (2) dxconsole, or (3) dtsession.
by stripey