CVE-2014-0895: IBM Spss Samplepower

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.

Affected products

  • IBM Spss Samplepower: version 3.0.1.0 only

Published 2014-03-16. Last modified 2026-06-17.