OCaml records
8 published records for vendor ocaml.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-126 Buffer Over-read1
- CWE-24 Path Traversal: '../filedir'1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-9838No exploit | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations ocaml · ocaml · CWE-190 | Critical9.8 | — | 4.1% | Apr 6, 2018 |
40Plan | CVE-2017-9772No exploit | Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaocaml · ocaml | Critical9.8 | — | 3.5% | Jun 23, 2017 |
38Monitor | CVE-2015-8869No exploit | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain senocaml · ocaml · CWE-119 | Critical9.1 | — | 5.3% | Jun 13, 2016 |
31Monitor | CVE-2009-2943No exploit | The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which mocaml · postgresql-ocaml | High7.5 | — | 2.2% | Oct 22, 2009 |
31Monitor | CVE-2017-9779Proof of concept | OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.ocaml · ocaml | High7.8 | — | 0.6% | Sep 7, 2017 |
31Monitor | CVE-2026-28364No exploit | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution ocaml · ocaml · CWE-126 | High7.8 | — | 0.3% | Feb 27, 2026 |
31Monitor | CVE-2026-41082No exploit | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.ocaml · opam · CWE-24 | High7.8 | — | 0.2% | Apr 16, 2026 |
20Monitor | CVE-2026-34353No exploit | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is prococaml · ocaml · CWE-190 | Medium5.1 | — | 0.1% | Mar 27, 2026 |
- CVE-2018-983840Plan
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations
CriticalCVSS 9.8No exploitEPSS 4%ocaml · ocamlApr 6, 2018
- CVE-2017-977240Plan
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in bina
CriticalCVSS 9.8No exploitEPSS 3%ocaml · ocamlJun 23, 2017
- CVE-2015-886938Monitor
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sen
CriticalCVSS 9.1No exploitEPSS 5%ocaml · ocamlJun 13, 2016
- CVE-2009-294331Monitor
The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which m
HighCVSS 7.5No exploitEPSS 2%ocaml · postgresql-ocamlOct 22, 2009
- CVE-2017-977931Monitor
OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.
HighCVSS 7.8Proof of conceptEPSS 1%ocaml · ocamlSep 7, 2017
- CVE-2026-2836431Monitor
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution
HighCVSS 7.8No exploitEPSS 0%ocaml · ocamlFeb 27, 2026
- CVE-2026-4108231Monitor
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
HighCVSS 7.8No exploitEPSS 0%ocaml · opamApr 16, 2026
- CVE-2026-3435320Monitor
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is proc
MediumCVSS 5.1No exploitEPSS 0%ocaml · ocamlMar 27, 2026