Inria's vulnerability profile centers on its OCaml programming language and related compiler tooling, a modestly represented but specialized footprint in the research and functional-programming ecosystem. The observed weakness classes—improper input validation and insecure temporary file handling—reflect the parser and file-system operations inherent to language implementations and development tools; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inria over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4119CRITICAL caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install. | Oct 26, 2021 | 9.8 | 31 | NO | NO |
CVE-2012-0839MEDIUM OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of | Feb 8, 2012 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inria.
Media articles that mention a CVE ID that affects a product developed by Inria — matched by CVE ID, not by vendor name.