<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:15:10.407367+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15262</id>
    <title>bdu:2026-15262</title>
    <updated>2026-10-02T16:15:10.443967+00:00</updated>
    <content>bdu:2026-15262</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-15043</id>
    <title>BELL-CVE-2026-15043</title>
    <updated>2026-10-02T16:15:10.444007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-15043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:15:10.444037+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336513</id>
    <title>EUVD-2026-336513</title>
    <updated>2026-10-02T16:15:10.444053+00:00</updated>
    <content>EUVD-2026-336513</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15043</id>
    <title>fkie_cve-2026-15043</title>
    <updated>2026-10-02T16:15:10.444064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text.</p>
<p>DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &lt;= was evaluated using Perl's ge operator, and &gt;= was evaluated using Perl's le operator.</p>
<p>SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.</p>
<p>The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &lt;=/&gt;= comparison silently returns the wrong rows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15043</id>
    <title>msrc_CVE-2026-15043 — DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text</title>
    <updated>2026-10-02T16:15:10.444097+00:00</updated>
    <content>msrc_CVE-2026-15043</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-15043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3183</id>
    <title>OESA-2026-3183 — perl-DBI security update</title>
    <updated>2026-10-02T16:15:10.444112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: perl-DBI, openEuler:24.03-LTS-SP1: perl-DBI, openEuler:24.03-LTS-SP3: perl-DBI, openEuler:24.03-LTS-SP4: perl-DBI, openEuler:20.03-LTS-SP4: perl-DBI</p>
<p>The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;quot;glue&amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.

Security Fix(es):</p>
<p>DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.</p>
<p>The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.</p>
<p>DBI version 1.650 sets a hard limit of 99,999 placeholders.(CVE-2026-14739)</p>
<p>DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;lt;= and &amp;gt;= SQL operators on text.</p>
<p>DBI::SQL::Nano, DBI&amp;apos;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;lt;= was evaluated using Perl&amp;apos;s ge operator, and &amp;gt;= was evaluated using Perl&amp;apos;s le operator.</p>
<p>SQL::Nano is the fallback query engine for DBI&amp;apos;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.</p>
<p>Th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11298-1</id>
    <title>openSUSE-SU-2026:11298-1 — perl-DBI-1.651.0-1.1 on GA media</title>
    <updated>2026-10-02T16:15:10.444160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-DBI-1.651.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11298-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22845-1</id>
    <title>SUSE-SU-2026:22845-1 — Security update for perl-DBI</title>
    <updated>2026-10-02T16:15:10.444177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl-DBI</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22845-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15043</id>
    <title>UBUNTU-CVE-2026-15043</title>
    <updated>2026-10-02T16:15:10.444192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl</p>
<p>DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &lt;= was evaluated using Perl's ge operator, and &gt;= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &lt;=/&gt;= comparison silently returns the wrong rows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</id>
    <title>WID-SEC-W-2026-3043 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:15:10.444223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043"/>
  </entry>
</feed>
