<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:33:24.145262+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:69112</id>
    <title>ALSA-2026:69112 — Important: perl-DBI:1.641 security update</title>
    <updated>2026-10-02T16:33:24.568491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: perl-DBI</p>
<p>The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.</p>
<p>Security Fix(es):</p>
<p>* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:69112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-73194</id>
    <title>BELL-CVE-2026-73194</title>
    <updated>2026-10-02T16:33:24.568554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-73194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0182</id>
    <title>ESSA-2026:0182 — Important: perl-DBI:1.641 security update</title>
    <updated>2026-10-02T16:33:24.568580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: perl-DBI:1.641 security update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354609</id>
    <title>EUVD-2026-354609</title>
    <updated>2026-10-02T16:33:24.568599+00:00</updated>
    <content>EUVD-2026-354609</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73194</id>
    <title>fkie_cve-2026-73194</title>
    <updated>2026-10-02T16:33:24.568611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.</p>
<p>preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, ":p%d", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.</p>
<p>Any caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73194</id>
    <title>msrc_CVE-2026-73194 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets th…</title>
    <updated>2026-10-02T16:33:24.568644+00:00</updated>
    <content>msrc_CVE-2026-73194</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-73194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</id>
    <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
    <updated>2026-10-02T16:33:24.568661+00:00</updated>
    <content>NCSC-2026-0375</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3477</id>
    <title>OESA-2026-3477 — perl-DBI security update</title>
    <updated>2026-10-02T16:33:24.568706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: perl-DBI</p>
<p>The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;quot;glue&amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.

Security Fix(es):</p>
<p>DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.</p>
<p>preparse reserves seven output bytes per input byte, the width of the longest &amp;apos;:p99999&amp;apos; expansion. The &amp;apos;:N&amp;apos; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;apos;:2147483648&amp;apos; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;apos;?&amp;apos; then expands through `sprintf(start, &amp;quot;:p%d&amp;quot;, idx++)` to &amp;apos;:p-2147483648&amp;apos;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.</p>
<p>Any caller that preparses an untrusted statement into &amp;apos;:pN&amp;apos; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;apos;?&amp;apos…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:69112</id>
    <title>RHSA-2026:69112 — Red Hat Security Advisory: perl-DBI:1.641 security update</title>
    <updated>2026-10-02T16:33:24.568746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:69112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:69112</id>
    <title>RLSA-2026:69112 — Important: perl-DBI:1.641 security update</title>
    <updated>2026-10-02T16:33:24.568763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: perl-DBI</p>
<p>The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.</p>
<p>Security Fix(es):</p>
<p>* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:69112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73194</id>
    <title>UBUNTU-CVE-2026-73194</title>
    <updated>2026-10-02T16:33:24.568787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl</p>
<p>DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing ':2147483648' leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following '?' then expands through `sprintf(start, ":p%d", idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into ':pN' style placeholders gets a heap out-of-bounds write that grows with the number of '?' marks following the poisoned placeholder. The '?' and '%s' return styles compare the parsed number against the expected sequence and error out, and are unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403</id>
    <title>WID-SEC-W-2026-3403 — Oracle Communications: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:33:24.568822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403"/>
  </entry>
</feed>
