haskell records
4 published records for vendor haskell.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-328 Use of Weak Hash1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-3566No exploit | Command injection vulnerability in programing languages on Microsoft Windows operating system.haskell · process library · CWE-77 | Critical9.8 | — | 6.9% | Apr 10, 2024 |
30Monitor | CVE-2021-4249No exploit | xml-conduit DOCTYPE Entity Expansion Parse.hs infinite loophaskell · xml-conduit · CWE-404 | High7.5 | — | 0.8% | Dec 18, 2022 |
29Monitor | CVE-2013-0243No exploit | haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connectionshaskell · hs-tls · CWE-20 | High7.4 | — | 1.0% | Dec 5, 2019 |
26Monitor | CVE-2022-3433No exploit | The aeson library is not safe to use to consume untrusted JSON input.haskell · aeson · CWE-328 | Medium6.5 | — | 0.8% | Oct 10, 2022 |
- CVE-2024-356641Plan
Command injection vulnerability in programing languages on Microsoft Windows operating system.
CriticalCVSS 9.8No exploitEPSS 7%haskell · process libraryApr 10, 2024
- CVE-2021-424930Monitor
xml-conduit DOCTYPE Entity Expansion Parse.hs infinite loop
HighCVSS 7.5No exploitEPSS 1%haskell · xml-conduitDec 18, 2022
- CVE-2013-024329Monitor
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
HighCVSS 7.4No exploitEPSS 1%haskell · hs-tlsDec 5, 2019
- CVE-2022-343326Monitor
The aeson library is not safe to use to consume untrusted JSON input.
MediumCVSS 6.5No exploitEPSS 1%haskell · aesonOct 10, 2022