Vulnerabilities
Vulnerable Software
Gnu:  >> Pspp  >> 0.10.1  Security Vulnerabilities
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
CVSS Score
2.9
EPSS Score
0.0
Published
2025-05-16
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
CVSS Score
4.5
EPSS Score
0.001
Published
2025-05-10
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.
CVSS Score
4.5
EPSS Score
0.001
Published
2025-05-10
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.
CVSS Score
2.9
EPSS Score
0.001
Published
2025-05-10
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.
CVSS Score
2.9
EPSS Score
0.0
Published
2025-05-03


Contact Us

Shodan ® - All rights reserved