This page lists publicly disclosed CVE vulnerabilities affecting perl dbi (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-14740 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds. | 9b29abf9-4ab0-4765-b253-1875cd9b441e | 9.1 | 0.41% | 2026-07-07 | 2026-07-10 |
| CVE-2026-14739 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders. | 9b29abf9-4ab0-4765-b253-1875cd9b441e | 9.8 | 0.40% | 2026-07-07 | 2026-07-10 |
| CVE-2026-14380 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three diffe | 9b29abf9-4ab0-4765-b253-1875cd9b441e | 8.8 | 0.49% | 2026-07-07 | 2026-07-10 |
| CVE-2026-9698 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow. | 9b29abf9-4ab0-4765-b253-1875cd9b441e | 9.8 | 0.45% | 2026-06-09 | 2026-07-23 |
| CVE-2026-10879 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. | 9b29abf9-4ab0-4765-b253-1875cd9b441e | 9.8 | 0.43% | 2026-06-05 | 2026-06-17 |
| CVE-2019-20919 | An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference. | [email protected] | 4.7 | 0.51% | 2020-09-17 | 2026-06-16 |
| CVE-2014-10402 | An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401. | [email protected] | 6.1 | 0.49% | 2020-09-16 | 2026-06-16 |
| CVE-2014-10401 | An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute. | [email protected] | 6.1 | 0.44% | 2020-09-11 | 2026-06-16 |
| CVE-2013-7491 | An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated. | [email protected] | 5.3 | 2.66% | 2020-09-11 | 2026-06-16 |
| CVE-2013-7490 | An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption. | [email protected] | 5.3 | 2.74% | 2020-09-11 | 2026-06-16 |