VYPR

Arrow

by Apache

Source repositories

CVEs (5)

  • CVE-2024-52338CriNov 28, 2024
    risk 0.57cvss 9.8epss 0.02

    Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example,…

  • CVE-2019-12410HigNov 8, 2019
    risk 0.49cvss 7.5epss 0.05

    While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The…

  • CVE-2019-12408HigNov 8, 2019
    risk 0.49cvss 7.5epss 0.03

    It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized memory being unintentionally…

  • CVE-2024-41178HigJul 23, 2024
    risk 0.42cvss 7.5epss 0.01

    Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.  On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity…

  • CVE-2026-25087HigFeb 17, 2026
    risk 0.39cvss 7.0epss 0.01

    Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as…