CVE-2025-8735
published 2025-08-08CVE-2025-8735: A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.14%
4.1th percentile
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
| gnu | cflow | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-8735: cflow - A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affe...
vendor_debian·2025·CVSS 4.8
CVE-2025-8735 [MEDIUM] CVE-2025-8735: cflow - A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affe...
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-9jpr-2g6g-wg42: A vulnerability classified as problematic was found in GNU cflow up to 1
ghsa_unreviewed·2025-08-08
CVE-2025-8735 [MEDIUM] CWE-404 GHSA-9jpr-2g6g-wg42: A vulnerability classified as problematic was found in GNU cflow up to 1
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
OSV
CVE-2025-8735: A vulnerability classified as problematic was found in GNU cflow up to 1
osv·2025-08-08·CVSS 4.8
CVE-2025-8735 [MEDIUM] CVE-2025-8735: A vulnerability classified as problematic was found in GNU cflow up to 1
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
No detection rules found.
No public exploits indexed.
https://drive.google.com/file/d/1Q_rDQSEl3cBu6SUbfqr9pV9cHgvKcXFI/view?usp=drive_linkhttps://lists.gnu.org/archive/html/bug-cflow/2025-07/msg00000.htmlhttps://vuldb.com/?ctiid.319231https://vuldb.com/?id.319231https://vuldb.com/?submit.622328https://www.gnu.org/https://www.openwall.com/lists/oss-security/2025/10/27/12
2025-08-08
Published