| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.
A template derived from untrusted input can read heap memory past the buffer and return it to the caller. |
| Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. |
| Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network. |
| Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. |
| Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
| Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
| Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. |