Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Pilot-qof Subscribe
Filtered by product Datafreedom-perl
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4997 1 Pilot-qof 1 Datafreedom-perl 2008-11-09 6.9 MEDIUM N/A
** DISPUTED ** dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely "an EXAMPLE used in the manpage."