<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:07:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69112 — Important: perl-DBI:1.641 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl-DBI&lt;/p&gt;
&lt;p&gt;The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl-DBI&lt;/p&gt;
&lt;p&gt;The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69112</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-73194</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-73194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-dbi, Alpaquita:25: perl-dbi, Alpaquita:stream: perl-dbi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-73194</guid>
    </item>
    <item>
      <title>ESSA-2026:0182 — Important: perl-DBI:1.641 security update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0182</link>
      <description>&lt;p&gt;Important: perl-DBI:1.641 security update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: perl-DBI:1.641 security update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0182</guid>
    </item>
    <item>
      <title>EUVD-2026-354609</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354609</link>
      <description>EUVD-2026-354609</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354609</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73194</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73194</link>
      <description>&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.&lt;/p&gt;
&lt;p&gt;preparse reserves seven output bytes per input byte, the width of the longest &amp;#39;:p99999&amp;#39; expansion. The &amp;#39;:N&amp;#39; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;#39;:2147483648&amp;#39; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;#39;?&amp;#39; then expands through `sprintf(start, &amp;#34;:p%d&amp;#34;, idx++)` to &amp;#39;:p-2147483648&amp;#39;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.&lt;/p&gt;
&lt;p&gt;Any caller that preparses an untrusted statement into &amp;#39;:pN&amp;#39; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;#39;?&amp;#39; marks following the poisoned placeholder. The &amp;#39;?&amp;#39; and &amp;#39;%s&amp;#39; return styles compare the parsed number against the expected sequence and error out, and are unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.&lt;/p&gt;
&lt;p&gt;preparse reserves seven output bytes per input byte, the width of the longest &amp;#39;:p99999&amp;#39; expansion. The &amp;#39;:N&amp;#39; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;#39;:2147483648&amp;#39; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;#39;?&amp;#39; then expands through `sprintf(start, &amp;#34;:p%d&amp;#34;, idx++)` to &amp;#39;:p-2147483648&amp;#39;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.&lt;/p&gt;
&lt;p&gt;Any caller that preparses an untrusted statement into &amp;#39;:pN&amp;#39; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;#39;?&amp;#39; marks following the poisoned placeholder. The &amp;#39;?&amp;#39; and &amp;#39;%s&amp;#39; return styles compare the parsed number against the expected sequence and error out, and are unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73194</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-73194 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets th…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73194</link>
      <description>msrc_CVE-2026-73194</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-73194</guid>
    </item>
    <item>
      <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</link>
      <description>NCSC-2026-0375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0375</guid>
    </item>
    <item>
      <title>OESA-2026-3477 — perl-DBI security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3477</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: perl-DBI&lt;/p&gt;
&lt;p&gt;The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;amp;quot;glue&amp;amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.&lt;/p&gt;
&lt;p&gt;preparse reserves seven output bytes per input byte, the width of the longest &amp;amp;apos;:p99999&amp;amp;apos; expansion. The &amp;amp;apos;:N&amp;amp;apos; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;amp;apos;:2147483648&amp;amp;apos; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;amp;apos;?&amp;amp;apos; then expands through `sprintf(start, &amp;amp;quot;:p%d&amp;amp;quot;, idx++)` to &amp;amp;apos;:p-2147483648&amp;amp;apos;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.&lt;/p&gt;
&lt;p&gt;Any caller that preparses an untrusted statement into &amp;amp;apos;:pN&amp;amp;apos; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;amp;apos;?&amp;amp;apos…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: perl-DBI&lt;/p&gt;
&lt;p&gt;The DBI is the standard database interface module for Perl. It defines a set of methods, variables and conventions that provide a consistent database interface independent of the actual database being used. It is important to remember that the DBI is just an interface. The DBI is a layer of &amp;amp;amp;quot;glue&amp;amp;amp;quot; between an application and one or more database driver modules. It is the driver modules which do most of the real work. The DBI provides a standard interface and framework for the drivers to operate within.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.&lt;/p&gt;
&lt;p&gt;preparse reserves seven output bytes per input byte, the width of the longest &amp;amp;apos;:p99999&amp;amp;apos; expansion. The &amp;amp;apos;:N&amp;amp;apos; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;amp;apos;:2147483648&amp;amp;apos; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;amp;apos;?&amp;amp;apos; then expands through `sprintf(start, &amp;amp;quot;:p%d&amp;amp;quot;, idx++)` to &amp;amp;apos;:p-2147483648&amp;amp;apos;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes.&lt;/p&gt;
&lt;p&gt;Any caller that preparses an untrusted statement into &amp;amp;apos;:pN&amp;amp;apos; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;amp;apos;?&amp;amp;apos…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3477</guid>
    </item>
    <item>
      <title>RHSA-2026:69112 — Red Hat Security Advisory: perl-DBI:1.641 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69112</link>
      <description>&lt;p&gt;perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69112</guid>
    </item>
    <item>
      <title>RLSA-2026:69112 — Important: perl-DBI:1.641 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl-DBI&lt;/p&gt;
&lt;p&gt;The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl-DBI&lt;/p&gt;
&lt;p&gt;The perl-DBI package provides the standard database interface module for the Perl programming language. It implements a database-independent interface, meaning it defines a consistent set of methods, variables, and conventions for database operations.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder (CVE-2026-73194)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69112</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73194</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl&lt;/p&gt;
&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest &amp;#39;:p99999&amp;#39; expansion. The &amp;#39;:N&amp;#39; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;#39;:2147483648&amp;#39; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;#39;?&amp;#39; then expands through `sprintf(start, &amp;#34;:p%d&amp;#34;, idx++)` to &amp;#39;:p-2147483648&amp;#39;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into &amp;#39;:pN&amp;#39; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;#39;?&amp;#39; marks following the poisoned placeholder. The &amp;#39;?&amp;#39; and &amp;#39;%s&amp;#39; return styles compare the parsed number against the expected sequence and error out, and are unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libdbi-perl, Ubuntu:Pro:16.04:LTS: libdbi-perl, Ubuntu:Pro:18.04:LTS: libdbi-perl, Ubuntu:Pro:20.04:LTS: libdbi-perl, Ubuntu:22.04:LTS: libdbi-perl, Ubuntu:24.04:LTS: libdbi-perl, Ubuntu:26.04:LTS: libdbi-perl&lt;/p&gt;
&lt;p&gt;DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest &amp;#39;:p99999&amp;#39; expansion. The &amp;#39;:N&amp;#39; branch parses the number with `atoi(src)` and assigns it to the binder counter with no range check, so a statement containing &amp;#39;:2147483648&amp;#39; leaves the counter negative (-2147483648 with glibc, where atoi wraps). Each following &amp;#39;?&amp;#39; then expands through `sprintf(start, &amp;#34;:p%d&amp;#34;, idx++)` to &amp;#39;:p-2147483648&amp;#39;, 14 bytes with the terminating NUL where the buffer budgets 7. The placeholder limit added in 1.650 tests the counter against 99,999, which a negative counter passes. Any caller that preparses an untrusted statement into &amp;#39;:pN&amp;#39; style placeholders gets a heap out-of-bounds write that grows with the number of &amp;#39;?&amp;#39; marks following the poisoned placeholder. The &amp;#39;?&amp;#39; and &amp;#39;%s&amp;#39; return styles compare the parsed number against the expected sequence and error out, and are unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73194</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3403 — Oracle Communications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403</guid>
    </item>
  </channel>
</rss>
