Gnu

Aspell

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 06.10.2026 10:57:59
  • Zuletzt bearbeitet 06.10.2026 15:03:59

GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose leng...

  • EPSS 0.12%
  • Veröffentlicht 06.10.2026 10:57:56
  • Zuletzt bearbeitet 06.10.2026 15:03:59

GNU Aspell contains an out-of-bounds read vulnerability in ReadOnlyDict::load() in readonly_ws.cpp. When loading a binary .rws dictionary file, it uses offset fields from the file header as byte indices into a heap buffer without validating their bou...

  • EPSS 0.14%
  • Veröffentlicht 06.10.2026 10:57:52
  • Zuletzt bearbeitet 06.10.2026 15:03:59

GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on t...

  • EPSS 0.55%
  • Veröffentlicht 20.07.2021 07:15:07
  • Zuletzt bearbeitet 21.11.2024 04:39:50

objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).

  • EPSS 1.74%
  • Veröffentlicht 27.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:38:27

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

  • EPSS 3.26%
  • Veröffentlicht 14.10.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:29

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

  • EPSS 0.92%
  • Veröffentlicht 06.08.2004 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:05:51

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or...