Skip to main content

Vendor/product archive

ibm / spss_statistics CVEs

Beta · best-effort

6 CVEs tagged to ibm / spss_statistics0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-31896

Published Mar 25, 2025

IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43855

Published Mar 8, 2024

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity and cause a denial of service.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38959

Published Nov 17, 2021

IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected direct…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8530

Published May 14, 2016

Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7489

Published Jan 1, 2016

IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifyi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0140

Published May 25, 2015

An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1