CVE-2012-5945: IBM Spss Samplepower

High severity, CVSS 9.3. EPSS: 3.5% chance of exploitation in the next 30 days.

Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property value.

Affected products

  • IBM Spss Samplepower: version 3.0.0.0 only

Published 2013-04-30. Last modified 2026-06-16.