The R Project maintains a statistical computing environment and language widely used in data science and research workflows, with vulnerabilities centered on its core interpreter and the CRAN package repository. The observed exposure involves buffer-overflow conditions, a classic memory-safety weakness that can arise in native components of the interpreter and contributed packages. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by R Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27637CRITICAL The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages inst | Jan 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2016-8714HIGH An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer o | Mar 10, 2017 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by R Project.
Media articles that mention a CVE ID that affects a product developed by R Project — matched by CVE ID, not by vendor name.