Security Advisories (11)
CVE-2020-14393 (2020-09-16)

A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.

CVE-2020-14392 (2020-06-17)

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

CVE-2019-20919 (2020-09-17)

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

CPANSA-DBI-2014-01 (2014-10-15)

DBD::File drivers open files from folders other than specifically passed using the f_dir attribute.

CVE-2005-0077 (2005-05-02)

Allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.

CVE-2014-10402 (2020-09-16)

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

CVE-2014-10401 (2020-09-11)

An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.

CVE-2013-7491 (2020-09-11)

An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.

CVE-2013-7490 (2020-09-11)

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.

CVE-2026-10879 (2026-06-05)

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

CVE-2026-9698 (2026-06-09)

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.

Documentation

A proxy server for the DBD::Proxy driver
Interactive command shell for the Perl DBI

Modules

DBI
Database independent interface for Perl UNAUTHORIZED
A bundle to install DBI and required modules. UNAUTHORIZED
A DBI driver for Microsoft ADO (Active Data Objects) UNAUTHORIZED
A proxy driver for the DBI UNAUTHORIZED
DBD Driver Writer's Guide UNAUTHORIZED
The Frequently Asked Questions for the Perl5 Database Interface UNAUTHORIZED
A package for displaying result tables UNAUTHORIZED
a server for the DBD::Proxy driver UNAUTHORIZED
Interactive command shell for the DBI UNAUTHORIZED
An experimental DBI emulation layer for Win32::ODBC
Win32::ODBC emulation layer for the DBI UNAUTHORIZED

Provides

in lib/DBD/ADO.pm UNAUTHORIZED
in lib/DBD/ADO.pm UNAUTHORIZED
in lib/DBD/ADO.pm UNAUTHORIZED
in Mac_changed/ExampleP.pm UNAUTHORIZED
in lib/DBD/ExampleP.pm UNAUTHORIZED
in Mac_changed/ExampleP.pm UNAUTHORIZED
in lib/DBD/ExampleP.pm UNAUTHORIZED
in Mac_changed/ExampleP.pm UNAUTHORIZED
in lib/DBD/ExampleP.pm UNAUTHORIZED
in Mac_changed/ExampleP.pm UNAUTHORIZED
in lib/DBD/ExampleP.pm UNAUTHORIZED
in lib/DBD/NullP.pm UNAUTHORIZED
in lib/DBD/NullP.pm UNAUTHORIZED
in lib/DBD/NullP.pm UNAUTHORIZED
in lib/DBD/NullP.pm UNAUTHORIZED
in lib/DBD/Proxy.pm UNAUTHORIZED
in lib/DBD/Proxy.pm UNAUTHORIZED
in lib/DBD/Proxy.pm UNAUTHORIZED
in lib/DBD/Sponge.pm UNAUTHORIZED
in lib/DBD/Sponge.pm UNAUTHORIZED
in lib/DBD/Sponge.pm UNAUTHORIZED
in lib/DBD/Sponge.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in DBI.pm UNAUTHORIZED
in lib/DBI/Format.pm UNAUTHORIZED
in lib/DBI/Format.pm UNAUTHORIZED
in lib/DBI/Format.pm UNAUTHORIZED
in lib/DBI/ProxyServer.pm UNAUTHORIZED
in lib/DBI/ProxyServer.pm UNAUTHORIZED
in lib/DBI/ProxyServer.pm UNAUTHORIZED
in lib/DBI/Shell.pm UNAUTHORIZED
in lib/DBI/Shell.pm UNAUTHORIZED