GNU / PSPP
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-5899 | GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heap | MEDIUM | 4.8 | Jun 9, 2025 |
| CVE-2025-5898 | GNU PSPP pspp-convert.c parse_variables_option out-of-bounds write | MEDIUM | 4.8 | Jun 9, 2025 |
| CVE-2025-5001 | GNU PSPP pspp-convert.c calloc integer overflow | MEDIUM | 4.8 | May 20, 2025 |
| CVE-2025-48188 | libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a… | MEDIUM | 5.5 | May 16, 2025 |
| CVE-2025-47816 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at… | CRITICAL | 9.1 | May 10, 2025 |
| CVE-2025-47815 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in… | CRITICAL | 9.8 | May 10, 2025 |
| CVE-2025-47814 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in… | CRITICAL | 9.8 | May 10, 2025 |
| CVE-2025-47229 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted… | MEDIUM | 5.5 | May 3, 2025 |
| CVE-2022-39831 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows att… | HIGH | 7.8 | Sep 5, 2022 |
| CVE-2022-39832 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers t… | HIGH | 7.8 | Sep 5, 2022 |
| CVE-2019-9211 | There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead… | MEDIUM | 6.5 | Feb 27, 2019 |
| CVE-2018-20230 | An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows att… | HIGH | 7.8 | Dec 19, 2018 |
| CVE-2017-12961 | There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remo… | HIGH | 7.5 | Aug 18, 2017 |
| CVE-2017-12960 | There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to r… | HIGH | 7.5 | Aug 18, 2017 |
| CVE-2017-12959 | There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a… | HIGH | 7.5 | Aug 18, 2017 |
| CVE-2017-12958 | There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote den… | HIGH | 7.5 | Aug 18, 2017 |
| CVE-2017-10792 | There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the… | MEDIUM | 6.5 | Jul 2, 2017 |
| CVE-2017-10791 | There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library co… | MEDIUM | 6.5 | Jul 2, 2017 |
Showing 1 to 16 of 16 CVEs