CVE-2006-0459
Last modified
CVE-2006-0459 is a vulnerability of currently unknown severity. flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.. EPSS estimates a 4.77% chance of exploitation in the next 30 days.
Description
flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Westes | Flex | <= 2.5.32 |
References
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://usn.ubuntu.com/260-1/Third Party Advisory
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://usn.ubuntu.com/260-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0459?
How severe is CVE-2006-0459?
How do I fix CVE-2006-0459?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0453The LDAP component in Fedora Directory Server 1.0 allow remo…
- CVE-2006-0454Linux kernel before 2.6.15.3 down to 2.6.12, while construct…
- CVE-2006-0455gpgv in GnuPG before 1.4.2.1, when using unattended signatur…
- CVE-2006-0456The strnlen_user function in Linux kernel before 2.6.16 on I…
- CVE-2006-0457Race condition in the (1) add_key, (2) request_key, and (3) …
- CVE-2006-0458The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10r…
- CVE-2006-0460Multiple buffer overflows in BomberClone before 0.11.6.2 all…
- CVE-2006-0461Cross-site scripting (XSS) vulnerability in core.input.php i…
- CVE-2006-0462SQL injection vulnerability in comentarios.php in AndoNET Bl…
- CVE-2006-0463Cross-site scripting (XSS) vulnerability in IdeoContent Mana…
- CVE-2006-0464Multiple SQL injection vulnerabilities in index.php in IdeoC…
- CVE-2006-0465Cross-site scripting (XSS) vulnerability in risultati_ricerc…
Are you affected by CVE-2006-0459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
