The R Foundation maintains the R statistical computing language and runtime, a narrowly scoped but widely embedded component in data-analysis and research workflows across academia and enterprise environments. Vulnerabilities in R have centered on improper link resolution during file access, a weakness class that reflects the language's file-handling operations and can affect downstream applications that invoke R for data processing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by R Foundation over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3931MEDIUM javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | Sep 4, 2008 | 6.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by R Foundation.
Media articles that mention a CVE ID that affects a product developed by R Foundation — matched by CVE ID, not by vendor name.