PatchSiren

R-Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH r-project CVE published 2026-04-12

CVE-2019-25695

CVE-2019-25695 is a local buffer overflow vulnerability in R 3.4.4 that allows attackers to execute arbitrary code by injecting malicious input into the GUI Preferences language field. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. The issue was published on April 12, 2026, and last modified on June 30, 2026. The CVE record and NVD detail provide more information about the v [truncated]

HIGH R-Project CVE published 2026-04-05

CVE-2019-25656

CVE-2019-25656 is a local buffer overflow vulnerability in the GUI Preferences dialog of R i386 3.5.0. The vulnerability allows local attackers to trigger a structured exception handler (SEH) overwrite by supplying malicious input in the 'Language for menus and messages' field. This can lead to code execution with calculator or arbitrary shellcode. The vulnerability has a CVSS score of 8.6 and is classifi [truncated]