Lucene search

K

Haskell Security Vulnerabilities

cve
cve

CVE-2024-3566

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are...

9.6AI Score

0.0004EPSS

2024-04-10 04:15 PM
34
cve
cve

CVE-2021-4249

A vulnerability was found in xml-conduit. It has been classified as problematic. Affected is an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs of the component DOCTYPE Entity Expansion Handler. The manipulation leads to infinite loop. It is possible to launch the attack...

7.5CVSS

7.6AI Score

0.001EPSS

2022-12-18 03:15 PM
26
cve
cve

CVE-2022-3433

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of...

6.5CVSS

6.3AI Score

0.001EPSS

2022-10-10 10:15 PM
23
2
cve
cve

CVE-2021-30502

The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with...

9.8CVSS

9.7AI Score

0.037EPSS

2021-04-25 03:15 AM
16
2
cve
cve

CVE-2013-0243

haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS...

7.4CVSS

7.3AI Score

0.001EPSS

2019-12-05 04:15 PM
21