Gnu Pspp vulnerabilities
18 known vulnerabilities affecting gnu/pspp.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2025-5898MEDIUMCVSS 4.8v82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb2025-06-09
CVE-2025-5898 [MEDIUM] CWE-119 CVE-2025-5898: A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb
A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5899MEDIUMCVSS 4.8v82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb2025-06-09
CVE-2025-5899 [MEDIUM] CWE-590 CVE-2025-5899: A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdff
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public
cvelistv5nvd
CVE-2025-5001MEDIUMCVSS 4.8v82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb2025-05-20
CVE-2025-5001 [MEDIUM] CWE-189 CVE-2025-5001: A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and
cvelistv5nvd
CVE-2025-48188MEDIUMCVSS 5.5≤ 2.0.12025-05-16
CVE-2025-48188 [LOW] CWE-125 CVE-2025-48188: libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-f
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
cvelistv5nvd
CVE-2025-47814CRITICALCVSS 9.8≤ 2.0.12025-05-10
CVE-2025-47814 [MEDIUM] CWE-122 CVE-2025-47814: libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in i
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
cvelistv5nvd
CVE-2025-47815CRITICALCVSS 9.8≤ 2.0.12025-05-10
CVE-2025-47815 [MEDIUM] CWE-122 CVE-2025-47815: libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in i
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.
cvelistv5nvd
CVE-2025-47816CRITICALCVSS 9.1≤ 2.0.12025-05-10
CVE-2025-47816 [LOW] CWE-125 CVE-2025-47816: libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.
cvelistv5nvd
CVE-2025-47229MEDIUMCVSS 5.5≤ 2.0.12025-05-03
CVE-2025-47229 [LOW] CWE-617 CVE-2025-47229: libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leav
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.
cvelistv5nvd
CVE-2022-39831HIGHCVSS 7.8v1.6.22022-09-05
CVE-2022-39831 [HIGH] CVE-2022-39831: An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_by
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
nvd
CVE-2022-39832HIGHCVSS 7.8v1.6.22022-09-05
CVE-2022-39832 [HIGH] CWE-787 CVE-2022-39832: An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_st
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2019-9211MEDIUMCVSS 6.5v1.2.02019-02-27
CVE-2019-9211 [MEDIUM] CWE-617 CVE-2019-9211: There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
nvd
CVE-2018-20230HIGHCVSS 7.8v1.2.02018-12-19
CVE-2018-20230 [HIGH] CWE-787 CVE-2018-20230: An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_by
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-12958HIGHCVSS 7.5v0.11.02017-08-18
CVE-2017-12958 [HIGH] CWE-125 CVE-2017-12958: There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp li
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
nvd
CVE-2017-12959HIGHCVSS 7.5v0.11.02017-08-18
CVE-2017-12959 [HIGH] CWE-617 CVE-2017-12959: There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the li
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
nvd
CVE-2017-12961HIGHCVSS 7.5v0.11.02017-08-18
CVE-2017-12961 [HIGH] CWE-20 CVE-2017-12961: There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libp
There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
nvd
CVE-2017-12960HIGHCVSS 7.5v0.11.02017-08-18
CVE-2017-12960 [HIGH] CWE-617 CVE-2017-12960: There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the l
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
nvd
CVE-2017-10792MEDIUMCVSS 6.5v0.10.5-pre22017-07-02
CVE-2017-10792 [MEDIUM] CWE-476 CVE-2017-10792: There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP b
There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2017-10791MEDIUMCVSS 6.5v0.10.5-pre22017-07-02
CVE-2017-10791 [MEDIUM] CWE-190 CVE-2017-10791: There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11
There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.
nvd