Lucene search

K
osvGoogleOSV:USN-4778-1
HistoryMar 15, 2021 - 8:54 p.m.

ocaml vulnerabilities

2021-03-1520:54:41
Google
osv.dev
11
ocaml
ubuntu 16.04 esm
vulnerability
denial of service
sensitive information
arbitrary code
crafted input
cve-2015-8869
cve-2018-9838

AI Score

7.8

Confidence

High

EPSS

0.022

Percentile

89.6%

It was discovered that OCaml mishandled sign extensions. A remote attacker
could use this vulnerability to steal sensitive information, cause a denial
of service (crash), or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 ESM. (CVE-2015-8869)

It was discovered that OCaml mishandled crafted input. An attacker could
use this vulnerability to cause a denial of service or possibly execute
arbitrary code. (CVE-2018-9838)