Pspp
Vendor:
First CVE: Jul 2, 2017 · Active for 9 years
16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pspp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2017
9 years ago
Most Recent CVE
May 20, 2025
430 days ago
CVE Severity & Scoring
Pspp16 CVEs
38%
44%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (37.5%)
Network10 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (62.5%)
Unknown0 (0.0%)
Required6 (37.5%)
Privileges Required
Low3 (18.8%)
High0 (0.0%)
None13 (81.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47815CRITICAL libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c. | May 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-47814CRITICAL libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c. | May 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-47816CRITICAL libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document | May 10, 2025 | 9.1 | 28 | NO | NO |
CVE-2022-39832HIGH An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of s | Sep 5, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-39831HIGH An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a den | Sep 5, 2022 | 7.8 | 26 | NO | NO |
CVE-2018-20230HIGH An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a den | Dec 19, 2018 | 7.8 | 24 | NO | NO |
CVE-2017-12961HIGH There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. | Aug 18, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-12960HIGH There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of servi | Aug 18, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-12959HIGH There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of serv | Aug 18, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-10791MEDIUM There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to | Jul 2, 2017 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Pspp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.2 | 2 | 7.8 | 0.5% | 0 | 0 |
| 1.2.0 | 2 | 7.2 | 1.4% | 0 | 0 |
| 0.11.0 | 4 | 7.5 | 1.3% | 0 | 0 |
| 0.10.5-pre2 | 2 | 6.5 | 1.6% | 0 | 0 |