← Back

Pspp

pspp

Vendor: Gnu • 16 CVEs

CVEs (16)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Pspp
Jun 17, 2026
May 20, 2025
4.8 MEDIUM· v4
5.5 MEDIUM· v3
1.7 LOW· v2
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argu...Show more
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.Show less
1Gnu
1Pspp
Jun 17, 2026
May 16, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
1Gnu
1Pspp
Jun 17, 2026
May 10, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.
1Gnu
1Pspp
Jun 17, 2026
May 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.
1Gnu
1Pspp
Jun 17, 2026
May 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
1Gnu
1Pspp
Jun 17, 2026
May 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/...Show more
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.Show less
2Fedoraproject
Gnu
2Fedora
Pspp
Jun 17, 2026
Sep 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly h...Show more
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.Show less
2Fedoraproject
Gnu
2Fedora
Pspp
Jun 17, 2026
Sep 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or po...Show more
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.Show less
3Fedoraproject
GnuSuse
3Backports
FedoraPspp
Jun 17, 2026
Feb 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
1Gnu
1Pspp
Nov 21, 2024
Dec 19, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or po...Show more
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.Show less
1Gnu
1Pspp
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
1Gnu
1Pspp
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
1Gnu
1Pspp
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
1Gnu
1Pspp
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
1Gnu
1Pspp
May 13, 2026
Jul 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data int...Show more
There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.Show less
1Gnu
1Pspp
May 13, 2026
Jul 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV form...Show more
There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.Show less