CVE-2014-9157

Description

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.899

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-9157 are affected in Graphviz (x64) 2.42.3Windows
rich set of graph drawing tools (USN-2435-1) graphviz_2.36.0-0ubuntu3.1_i386.debLinux
rich set of graph drawing tools (USN-2435-1) graphviz_2.36.0-0ubuntu3.1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234