CVE-2026-56390
- EPSS 0.13%
- Veröffentlicht 29.07.2026 09:40:03
- Zuletzt bearbeitet 30.07.2026 16:28:33
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-suppl...
CVE-2026-56389
- EPSS 0.15%
- Veröffentlicht 29.07.2026 09:39:52
- Zuletzt bearbeitet 30.07.2026 16:28:33
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %...
CVE-2025-8734
- EPSS 0.02%
- Veröffentlicht 08.08.2025 18:15:29
- Zuletzt bearbeitet 04.11.2025 00:15:44
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Additional analysis indicates that the files refe...
CVE-2025-8733
- EPSS 0.02%
- Veröffentlicht 08.08.2025 17:32:06
- Zuletzt bearbeitet 04.11.2025 00:15:43
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Additional analysis indicates that the files refe...
CVE-2020-24240
- EPSS 1.27%
- Veröffentlicht 25.08.2020 14:15:16
- Zuletzt bearbeitet 21.11.2024 05:14:32
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behav...
CVE-2020-14150
- EPSS 0.39%
- Veröffentlicht 15.06.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:44
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. Th...