VendorsPerldbiany version
Vulnerabilities

Perl DBI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-9698
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
Published 2026-06-09 · Modified
9.8EPSS 0.008
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Published 2026-06-05 · Analyzed
9.8EPSS 0.005
CVE-2026-14739
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Published 2026-07-07 · Analyzed
9.8EPSS 0.004
CVE-2026-14740
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Published 2026-07-07 · Analyzed
9.1EPSS 0.004
CVE-2026-14380
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Published 2026-07-07 · Modified
8.8EPSS 0.005
CVE-2014-10402
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Published 2020-09-16 · Modified
6.1EPSS 0.005
CVE-2014-10401
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Published 2020-09-11 · Modified
6.1EPSS 0.004
CVE-2013-7490
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
Published 2020-09-11 · Modified
5.3EPSS 0.027
CVE-2013-7491
An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.
Published 2020-09-11 · Modified
5.3EPSS 0.027
CVE-2019-20919
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
Published 2020-09-17 · Modified
4.7EPSS 0.005