VYPR
Vendor

Haskell

Products
7
CVEs
4
Across products
5
Status
Private

Products

7

Recent CVEs

4
  • CVE-2024-3566CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.07

    A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

  • CVE-2013-0243HigDec 5, 2019
    risk 0.48cvss 7.4epss 0.01

    haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections

  • CVE-2022-3433MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.01

    The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

  • CVE-2021-4249MedDec 18, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in xml-conduit. It has been classified as problematic. Affected is an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs of the component DOCTYPE Entity Expansion Handler. The manipulation leads to infinite loop. It is possible to…