Search CVE reports
1 – 6 of 6 results
R i386 3.5.0 contains a local buffer overflow vulnerability in the GUI Preferences dialog that allows local attackers to trigger a structured exception handler (SEH) overwrite by supplying malicious input. Attackers can craft a...
1 affected package
r-base
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| r-base | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.
1 affected package
node-cipher-base
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| node-cipher-base | Fixed | Fixed | Fixed | Fixed |
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R...
1 affected package
r-base
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| r-base | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
The R programming languageās default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the...
1 affected package
r-base
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| r-base | Not affected | Not affected | Vulnerable | Vulnerable |
Some fixes available 2 of 6
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An...
1 affected package
r-base
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| r-base | — | Not affected | Not affected | Not affected |
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
2 affected packages
r-base, r-base-core-ra
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| r-base | — | Not affected | Not affected | Not affected |
| r-base-core-ra | — | — | — | — |