CVE-2026-75820
- EPSS 0.13%
- Veröffentlicht 06.10.2026 10:57:59
- Zuletzt bearbeitet 06.10.2026 15:03:59
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose leng...
CVE-2026-75819
- EPSS 0.12%
- Veröffentlicht 06.10.2026 10:57:56
- Zuletzt bearbeitet 06.10.2026 15:03:59
GNU Aspell contains an out-of-bounds read vulnerability in ReadOnlyDict::load() in readonly_ws.cpp. When loading a binary .rws dictionary file, it uses offset fields from the file header as byte indices into a heap buffer without validating their bou...
CVE-2026-75818
- EPSS 0.14%
- Veröffentlicht 06.10.2026 10:57:52
- Zuletzt bearbeitet 06.10.2026 15:03:59
GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on t...
CVE-2019-25051
- EPSS 0.55%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:50
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
CVE-2019-20433
- EPSS 1.74%
- Veröffentlicht 27.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:27
libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.
CVE-2019-17544
- EPSS 3.26%
- Veröffentlicht 14.10.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:29
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
CVE-2004-0548
- EPSS 0.92%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:51
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or...