Vulnerabilities > GNU > Cflow

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-2789 Improper Resource Shutdown or Release vulnerability in GNU Cflow 1.7
A vulnerability was found in GNU cflow 1.7.
network
low complexity
gnu CWE-404
7.5
2021-05-18 CVE-2020-23856 Use After Free vulnerability in multiple products
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
local
low complexity
gnu fedoraproject CWE-416
5.5
2019-09-09 CVE-2019-16166 Out-of-bounds Read vulnerability in GNU Cflow 1.5/1.6
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
network
low complexity
gnu CWE-125
6.5
2019-09-09 CVE-2019-16165 Use After Free vulnerability in GNU Cflow 1.5/1.6
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
network
low complexity
gnu CWE-416
6.5