CVE-2025-5899
published 2025-06-09CVE-2025-5899: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function…
PriorityP429medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.14%
3.7th percentile
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pspp | — | — |
| gnu | pspp | — | — |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.8MEDIUM
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-5897
vendor_chrome·2026-04-07·CVSS 4.3
CVE-2026-5897 [LOW] Stable Channel Update for Desktop: CVE-2026-5897
Stable Channel Update for Desktop
CVE-2026-5897: Incorrect security UI in Downloads. Reported by Farras Givari on 2025-05-24 [TBD][ 470295118 ] Low CVE-2026-5898: Incorrect security UI in Omnibox
Reported by saidinahikam032 on 2025-12-19 [TBD][ 474817168 ] Low CVE-2026-5899: Incorrect security UI in History Navigation
Severity: low
Debian
CVE-2025-5899: pspp - A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7a...
vendor_debian·2025·CVSS 4.8
CVE-2025-5899 [MEDIUM] CVE-2025-5899: pspp - A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7a...
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-65vc-89h4-wvx6: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
ghsa_unreviewed·2025-06-10
CVE-2025-5899 [MEDIUM] CWE-590 GHSA-65vc-89h4-wvx6: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
OSV
CVE-2025-5899: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
osv·2025-06-09·CVSS 4.8
CVE-2025-5899 [MEDIUM] CVE-2025-5899: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
No detection rules found.
No public exploits indexed.
2025-06-09
Published