Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-0459
Description:flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
Test IDs: 1.3.6.1.4.1.25623.1.0.56423   1.3.6.1.4.1.25623.1.0.56415   1.3.6.1.4.1.25623.1.0.56472  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-0459
16896
http://www.securityfocus.com/bid/16896
19071
http://secunia.com/advisories/19071
19126
http://secunia.com/advisories/19126
19228
http://secunia.com/advisories/19228
19424
http://secunia.com/advisories/19424
23440
http://www.osvdb.org/23440
570
http://securityreason.com/securityalert/570
ADV-2006-0770
http://www.vupen.com/english/advisories/2006/0770
DSA-1020
http://www.us.debian.org/security/2006/dsa-1020
GLSA-200603-07
http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml
USN-260-1
https://usn.ubuntu.com/260-1/
[flex-announce] 20060222 flex 2.5.33 released
http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announce
flex-bypass-security(24995)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24995
http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download
http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download




© 1998-2025 E-Soft Inc. All rights reserved.