Skip to main content

Vendor/product archive

gnu / pspp CVEs

Beta · best-effort

16 CVEs tagged to gnu / pspp0 Critical, 7 High, 6 Medium, 3 Low, 0 Unrated.

CVE-2025-5001

Published May 20, 2025

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file psp…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48188

Published May 16, 2025

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer o…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47816

Published May 10, 2025

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a documen…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47815

Published May 10, 2025

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47814

Published May 10, 2025

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47229

Published May 3, 2025

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39832

Published Sep 5, 2022

An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39831

Published Sep 5, 2022

An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20230

Published Dec 19, 2018

An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12961

Published Aug 18, 2017

There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12960

Published Aug 18, 2017

There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12959

Published Aug 18, 2017

There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12958

Published Aug 18, 2017

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10792

Published Jul 2, 2017

There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when at…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10791

Published Jul 2, 2017

There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1