CVE-2026-9698Critical· 9.8▾ MidnightDBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that c…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.5%
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
dbi < 1.648Upgrade past the affected range:
dbi 1.648Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22184High· 7.8zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz
CVE-2026-78030Critical· 9.8DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…
CVE-2026-14380High· 8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…
CVE-2026-55301High· 8.4In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management
CVE-2026-64784Medium· 4.3An out-of-bounds access issue was addressed with improved bounds checking