Записи OCaml
8 опубликованных записей вендора ocaml.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-126 Buffer Over-read1
- CWE-24 Path Traversal: '../filedir'1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-9838Эксплойта нет | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations ocaml · ocaml · CWE-190 | Критическая9,8 | — | 4,1 % | 6 апр. 2018 г. |
40В плане | CVE-2017-9772Эксплойта нет | Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaocaml · ocaml | Критическая9,8 | — | 3,5 % | 23 июн. 2017 г. |
38Наблюдать | CVE-2015-8869Эксплойта нет | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain senocaml · ocaml · CWE-119 | Критическая9,1 | — | 5,3 % | 13 июн. 2016 г. |
31Наблюдать | CVE-2009-2943Эксплойта нет | The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which mocaml · postgresql-ocaml | Высокая7,5 | — | 2,2 % | 22 окт. 2009 г. |
31Наблюдать | CVE-2017-9779Proof of concept | OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.ocaml · ocaml | Высокая7,8 | — | 0,6 % | 7 сент. 2017 г. |
31Наблюдать | CVE-2026-28364Эксплойта нет | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution ocaml · ocaml · CWE-126 | Высокая7,8 | — | 0,3 % | 27 февр. 2026 г. |
31Наблюдать | CVE-2026-41082Эксплойта нет | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.ocaml · opam · CWE-24 | Высокая7,8 | — | 0,2 % | 16 апр. 2026 г. |
20Наблюдать | CVE-2026-34353Эксплойта нет | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is prococaml · ocaml · CWE-190 | Средняя5,1 | — | 0,1 % | 27 мар. 2026 г. |
- CVE-2018-983840В плане
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ocaml · ocaml6 апр. 2018 г.
- CVE-2017-977240В плане
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in bina
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ocaml · ocaml23 июн. 2017 г.
- CVE-2015-886938Наблюдать
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sen
КритическаяCVSS 9,1Эксплойта нетEPSS 5 %ocaml · ocaml13 июн. 2016 г.
- CVE-2009-294331Наблюдать
The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which m
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ocaml · postgresql-ocaml22 окт. 2009 г.
- CVE-2017-977931Наблюдать
OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %ocaml · ocaml7 сент. 2017 г.
- CVE-2026-2836431Наблюдать
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ocaml · ocaml27 февр. 2026 г.
- CVE-2026-4108231Наблюдать
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ocaml · opam16 апр. 2026 г.
- CVE-2026-3435320Наблюдать
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is proc
СредняяCVSS 5,1Эксплойта нетEPSS 0 %ocaml · ocaml27 мар. 2026 г.