ocaml kayıtları
ocaml üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-126 Buffer Over-read1
- CWE-24 Path Traversal: '../filedir'1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-9838İstismar yok | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations ocaml · ocaml · CWE-190 | Kritik9,8 | — | %4,1 | 6 Nis 2018 |
40Planlayın | CVE-2017-9772İstismar yok | Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaocaml · ocaml | Kritik9,8 | — | %3,5 | 23 Haz 2017 |
38İzleyin | CVE-2015-8869İstismar yok | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain senocaml · ocaml · CWE-119 | Kritik9,1 | — | %5,3 | 13 Haz 2016 |
31İzleyin | CVE-2009-2943İstismar yok | The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which mocaml · postgresql-ocaml | Yüksek7,5 | — | %2,2 | 22 Eki 2009 |
31İzleyin | CVE-2017-9779Kavram kanıtı | OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.ocaml · ocaml | Yüksek7,8 | — | %0,6 | 7 Eyl 2017 |
31İzleyin | CVE-2026-28364İstismar yok | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution ocaml · ocaml · CWE-126 | Yüksek7,8 | — | %0,3 | 27 Şub 2026 |
31İzleyin | CVE-2026-41082İstismar yok | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.ocaml · opam · CWE-24 | Yüksek7,8 | — | %0,2 | 16 Nis 2026 |
20İzleyin | CVE-2026-34353İstismar yok | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is prococaml · ocaml · CWE-190 | Orta5,1 | — | %0,1 | 27 Mar 2026 |
- CVE-2018-983840Planlayın
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations
KritikCVSS 9,8İstismar yokEPSS %4ocaml · ocaml6 Nis 2018
- CVE-2017-977240Planlayın
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in bina
KritikCVSS 9,8İstismar yokEPSS %3ocaml · ocaml23 Haz 2017
- CVE-2015-886938İzleyin
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sen
KritikCVSS 9,1İstismar yokEPSS %5ocaml · ocaml13 Haz 2016
- CVE-2009-294331İzleyin
The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which m
YüksekCVSS 7,5İstismar yokEPSS %2ocaml · postgresql-ocaml22 Eki 2009
- CVE-2017-977931İzleyin
OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact.
YüksekCVSS 7,8Kavram kanıtıEPSS %1ocaml · ocaml7 Eyl 2017
- CVE-2026-2836431İzleyin
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution
YüksekCVSS 7,8İstismar yokEPSS %0ocaml · ocaml27 Şub 2026
- CVE-2026-4108231İzleyin
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
YüksekCVSS 7,8İstismar yokEPSS %0ocaml · opam16 Nis 2026
- CVE-2026-3435320İzleyin
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is proc
OrtaCVSS 5,1İstismar yokEPSS %0ocaml · ocaml27 Mar 2026