Flex: The Fast Lexical Analyzer 2.5.25

CPE Details

Flex: The Fast Lexical Analyzer 2.5.25
2.5.25
2023-10-06
15h12 +00:00
2023-10-06
15h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:westes:flex:2.5.25:*:*:*:*:*:*:*

Informations

Vendor

westes

Product

flex

Version

2.5.25

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-6354 2016-09-21 12h00 +00:00 Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
9.8
Critical
CVE-2006-0459 2006-03-29 21h00 +00:00 flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
7.5