<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:13:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15262</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15262</link>
      <description>bdu:2026-15262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15262</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-15043</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-15043</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-15043</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-336513</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336513</link>
      <description>EUVD-2026-336513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336513</guid>
    </item>
    <item>
      <title>fkie_cve-2026-15043</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15043</link>
      <description>&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;lt;= and &amp;gt;= SQL operators on text.&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano, DBI&amp;#39;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;lt;= was evaluated using Perl&amp;#39;s ge operator, and &amp;gt;= was evaluated using Perl&amp;#39;s le operator.&lt;/p&gt;
&lt;p&gt;SQL::Nano is the fallback query engine for DBI&amp;#39;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.&lt;/p&gt;
&lt;p&gt;The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &amp;lt;=/&amp;gt;= comparison silently returns the wrong rows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;lt;= and &amp;gt;= SQL operators on text.&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano, DBI&amp;#39;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;lt;= was evaluated using Perl&amp;#39;s ge operator, and &amp;gt;= was evaluated using Perl&amp;#39;s le operator.&lt;/p&gt;
&lt;p&gt;SQL::Nano is the fallback query engine for DBI&amp;#39;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.&lt;/p&gt;
&lt;p&gt;The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &amp;lt;=/&amp;gt;= comparison silently returns the wrong rows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-15043</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-15043 — DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15043</link>
      <description>msrc_CVE-2026-15043</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-15043</guid>
    </item>
    <item>
      <title>OESA-2026-3183 — perl-DBI security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: perl-DBI, openEuler:24.03-LTS-SP1: perl-DBI, openEuler:24.03-LTS-SP3: perl-DBI, openEuler:24.03-LTS-SP4: perl-DBI, openEuler:20.03-LTS-SP4: perl-DBI&lt;/p&gt;
&lt;p&gt;The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;amp;quot;glue&amp;amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.&lt;/p&gt;
&lt;p&gt;DBI version 1.650 sets a hard limit of 99,999 placeholders.(CVE-2026-14739)&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;amp;lt;= and &amp;amp;gt;= SQL operators on text.&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano, DBI&amp;amp;apos;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;amp;lt;= was evaluated using Perl&amp;amp;apos;s ge operator, and &amp;amp;gt;= was evaluated using Perl&amp;amp;apos;s le operator.&lt;/p&gt;
&lt;p&gt;SQL::Nano is the fallback query engine for DBI&amp;amp;apos;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.&lt;/p&gt;
&lt;p&gt;Th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: perl-DBI, openEuler:24.03-LTS-SP1: perl-DBI, openEuler:24.03-LTS-SP3: perl-DBI, openEuler:24.03-LTS-SP4: perl-DBI, openEuler:20.03-LTS-SP4: perl-DBI&lt;/p&gt;
&lt;p&gt;The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;amp;quot;glue&amp;amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.&lt;/p&gt;
&lt;p&gt;DBI version 1.650 sets a hard limit of 99,999 placeholders.(CVE-2026-14739)&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;amp;lt;= and &amp;amp;gt;= SQL operators on text.&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano, DBI&amp;amp;apos;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;amp;lt;= was evaluated using Perl&amp;amp;apos;s ge operator, and &amp;amp;gt;= was evaluated using Perl&amp;amp;apos;s le operator.&lt;/p&gt;
&lt;p&gt;SQL::Nano is the fallback query engine for DBI&amp;amp;apos;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.&lt;/p&gt;
&lt;p&gt;Th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3183</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11298-1 — perl-DBI-1.651.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11298-1</link>
      <description>&lt;p&gt;perl-DBI-1.651.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-DBI-1.651.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11298-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22845-1 — Security update for perl-DBI</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22845-1</link>
      <description>&lt;p&gt;Security update for perl-DBI&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl-DBI&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22845-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-15043</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15043</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;lt;= and &amp;gt;= SQL operators on text. DBI::SQL::Nano, DBI&amp;#39;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;lt;= was evaluated using Perl&amp;#39;s ge operator, and &amp;gt;= was evaluated using Perl&amp;#39;s le operator. SQL::Nano is the fallback query engine for DBI&amp;#39;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &amp;lt;=/&amp;gt;= comparison silently returns the wrong rows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl&lt;/p&gt;
&lt;p&gt;DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &amp;lt;= and &amp;gt;= SQL operators on text. DBI::SQL::Nano, DBI&amp;#39;s built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, &amp;lt;= was evaluated using Perl&amp;#39;s ge operator, and &amp;gt;= was evaluated using Perl&amp;#39;s le operator. SQL::Nano is the fallback query engine for DBI&amp;#39;s file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted &amp;lt;=/&amp;gt;= comparison silently returns the wrong rows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15043</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3043 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</guid>
    </item>
  </channel>
</rss>
