Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Perl Number Of NVD 43 CRITICAL 12 HIGH 18 MEDIUM 12 LOW 1
URL https://www.perl.org/
Explanation Perl is an advanced, feature-rich programming language with over 30 years of development experience.
Perl runs on over 100 platforms, from portable to mainframe, and is suitable for both rapid prototyping and large-scale development projects.

The above text is a translation of the English version at [https://www.perl.org/about.html].

Perl has long been used for server backend scripting and also as a server-side programming language for web applications.
In recent years, other languages such as PHP and Python have come into use.

The y in the Perl version notation x.y.z is even for the regular version and odd for the development version.
Tag
  • Artistic License
  • オープンソース

Add Information URL
No Type Name URL
1 https://www.perl.org/get.html
2 https://github.com/Perl/perl5
3 http://www.cpan.org/src/
4 https://japan.perlassociation.org/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
41 Perl 5 5.43.5 Nov. 20, 2025 9 16 11 1
42 Perl 2 2.18.1 7 11 4 1
43 Perl 1 1.49 7 12 4 1
44 Perl 0 0.1 7 11 4 1
45 Perl - - 7 11 4 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
41 -
5.0
MEDIUM Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOT… CWE-399
 Resource Management Errors
CVE-2008-1927 cpe:2.3:a:perl:perl:5.8.8:* 2026-04-23 09:35
2008-04-24
Show GitHub Exploit DB Packet Storm
42 -
4.6
MEDIUM Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format strin… CWE-189
Numeric Errors
CVE-2005-3962 cpe:2.3:a:perl:perl:5.9.2:*
cpe:2.3:a:perl:perl:5.8.6:*
2018-10-20 00:39
2005-12-2
Show GitHub Exploit DB Packet Storm
43 5.5
2.1
MEDIUM
Local
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file. CWE-59
Link Following
CVE-1999-1386 cpe:2.3:a:perl:perl:*:* 5.004_04 2024-01-27 01:54
1999-12-31
Show GitHub Exploit DB Packet Storm