CVE-2025-8735 Information
Aug 09, 2025
cve
Description
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Reference
https://drive.google.com/file/d/1Q_rDQSEl3cBu6SUbfqr9pV9cHgvKcXFI/view?usp=drive_link https://lists.gnu.org/archive/html/bug-cflow/2025-07/msg00000.html https://vuldb.com/?ctiid.319231 https://vuldb.com/?id.319231 https://vuldb.com/?submit.622328 https://www.gnu.org/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
3.3
Related CNNVD
CNNVD-202508-786 (Published: 2025-08-08)
Share on: