← back
CVE-2025-8736

GNU cflow Lexer c.c yylex buffer overflow

CVSS 4.8 MEDIUMEPSS 0.1%CWE-119CWE-120
A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
GNU · cflow

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →