Skip to content
Noroxi

OCaml records

8 published records for vendor ocaml.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
87.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations

    CriticalCVSS 9.8No exploitEPSS 4%

    ocaml · ocamlApr 6, 2018

  • Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in bina

    CriticalCVSS 9.8No exploitEPSS 3%

    ocaml · ocamlJun 23, 2017

  • CVE-2015-8869
    38Monitor

    OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sen

    CriticalCVSS 9.1No exploitEPSS 5%

    ocaml · ocamlJun 13, 2016

  • CVE-2009-2943
    31Monitor

    The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which m

    HighCVSS 7.5No exploitEPSS 2%

    ocaml · postgresql-ocamlOct 22, 2009

  • CVE-2017-9779
    31Monitor

    OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.

    HighCVSS 7.8Proof of conceptEPSS 1%

    ocaml · ocamlSep 7, 2017

  • In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution

    HighCVSS 7.8No exploitEPSS 0%

    ocaml · ocamlFeb 27, 2026

  • In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

    HighCVSS 7.8No exploitEPSS 0%

    ocaml · opamApr 16, 2026

  • In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is proc

    MediumCVSS 5.1No exploitEPSS 0%

    ocaml · ocamlMar 27, 2026