Hmbrand Dbi vulnerabilities
5 known vulnerabilities affecting hmbrand/dbi.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1
Vulnerabilities
Page 1 of 1
CVE-2026-14380P2HIGHCVSS 8.8fixed in 1.6502026-07-07
CVE-2026-14380 [HIGH] CWE-95 CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.
When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name.
Any caller-influenced value that reaches the Profile
nvd
CVE-2026-10879P3CRITICALCVSS 9.8fixed in 1.6502026-06-05
CVE-2026-10879 [CRITICAL] CWE-787 CVE-2026-10879: DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more tha
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.
The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et c
nvd
CVE-2026-14740P3CRITICALCVSS 9.1fixed in 1.6502026-07-07
CVE-2026-14740 [CRITICAL] CWE-125 CVE-2026-14740: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.
The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds a
nvd
CVE-2026-60082P3CRITICALCVSS 9.1fixed in 1.6512026-07-14
CVE-2026-60082 [CRITICAL] CWE-125 CVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When t
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
nvd
CVE-2026-9698P3CRITICALCVSS 9.8fixed in 1.6482026-06-09
CVE-2026-9698 [CRITICAL] CWE-787 CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
nvd