Gnu

Bison

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 29.07.2026 09:40:03
  • Zuletzt bearbeitet 30.07.2026 16:28:33

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-suppl...

  • EPSS 0.15%
  • Veröffentlicht 29.07.2026 09:39:52
  • Zuletzt bearbeitet 30.07.2026 16:28:33

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %...

  • EPSS 0.02%
  • Veröffentlicht 08.08.2025 18:15:29
  • Zuletzt bearbeitet 04.11.2025 00:15:44

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Additional analysis indicates that the files refe...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.08.2025 17:32:06
  • Zuletzt bearbeitet 04.11.2025 00:15:43

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Additional analysis indicates that the files refe...

  • EPSS 1.27%
  • Veröffentlicht 25.08.2020 14:15:16
  • Zuletzt bearbeitet 21.11.2024 05:14:32

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behav...

  • EPSS 0.39%
  • Veröffentlicht 15.06.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:44

GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. Th...