← Back

Cflow

cflow

Vendor: Gnu • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Cflow
Jun 17, 2026
May 18, 2023
N/A· v4
7.5 HIGH· v3
2.7 LOW· v2
A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The ex...Show more
A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-229373 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
2Fedoraproject
Gnu
2Cflow
Fedora
Jun 17, 2026
May 18, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
1Gnu
1Cflow
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
1Gnu
1Cflow
Jun 17, 2026
Sep 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.