gnu pspp CVE Vulnerabilities (16)

CVEs: 16 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting gnu pspp (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 116 of 16 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-5001 A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. [email protected] 4.8 0.11% 2025-05-20 2025-06-17
CVE-2025-48188 libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read. [email protected] 2.9 0.07% 2025-05-16 2025-07-17
CVE-2025-47816 libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document. [email protected] 2.9 0.23% 2025-05-10 2025-06-16
CVE-2025-47815 libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c. [email protected] 4.5 0.23% 2025-05-10 2025-06-12
CVE-2025-47814 libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c. [email protected] 4.5 0.23% 2025-05-10 2025-06-12
CVE-2025-47229 libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code. [email protected] 2.9 0.01% 2025-05-03 2025-07-18
CVE-2022-39832 An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. [email protected] 7.8 0.07% 2022-09-05 2024-11-21
CVE-2022-39831 An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230. [email protected] 7.8 0.07% 2022-09-05 2024-11-21
CVE-2019-9211 There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service. [email protected] 6.5 0.53% 2019-02-27 2024-11-21
CVE-2018-20230 An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. [email protected] 7.8 0.23% 2018-12-19 2024-11-21
CVE-2017-12961 There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. [email protected] 7.5 0.27% 2017-08-18 2026-05-13
CVE-2017-12960 There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. [email protected] 7.5 0.16% 2017-08-18 2026-05-13
CVE-2017-12959 There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack. [email protected] 7.5 0.16% 2017-08-18 2026-05-13
CVE-2017-12958 There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. [email protected] 7.5 0.27% 2017-08-18 2026-05-13
CVE-2017-10792 There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack. [email protected] 6.5 0.47% 2017-07-02 2026-05-13
CVE-2017-10791 There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack. [email protected] 6.5 0.34% 2017-07-02 2026-05-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence