Vulnerabilities (CVE)

Filtered by vendor Pilot-qof Subscribe
Filtered by product Datafreedom-perl
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4997 1 Pilot-qof 1 Datafreedom-perl 2024-05-17 6.9 MEDIUM N/A
** DISPUTED ** dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely "an EXAMPLE used in the manpage."