CVE-2016-6354

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
8.0
westesflex
𝑥
≤ 2.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
flex
bookworm
2.6.4-8.2
fixed
bullseye
2.6.4-8
fixed
sid
2.6.4-8.2
fixed
trixie
2.6.4-8.2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flex
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
precise
not-affected
trusty
dne
wily
ignored
xenial
needed
yakkety
not-affected
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise desktop 15 SP1
60.6.2-3.32.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.87.1
fixed
suse enterprise desktop 15 SP3
78.10.0-8.38.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise desktop 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise desktop 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise desktop 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise sap 15 SP1
60.6.2-3.32.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.87.1
fixed
suse enterprise sap 15 SP3
78.10.0-8.38.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise sap 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise sap 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise sap 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 15
52.7.3-1.35
fixed
suse enterprise server 15 SP1
60.6.2-3.32.1
fixed
suse enterprise server 15 SP2
68.8.0-3.87.1
fixed
suse enterprise server 15 SP3
78.10.0-8.38.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise server 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise server 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise server 15 SP7
128.9.0-150200.152.176.1
fixed
MozillaFirefox-devel
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise desktop 15 SP1
60.6.2-3.32.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.87.1
fixed
suse enterprise desktop 15 SP3
78.10.0-8.38.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise desktop 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise desktop 15 SP6
102.12.0-150200.152.90.1
fixed
suse enterprise desktop 15 SP7
102.12.0-150200.152.90.1
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise sap 15 SP1
60.6.2-3.32.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.87.1
fixed
suse enterprise sap 15 SP3
78.10.0-8.38.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise sap 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise sap 15 SP6
102.12.0-150200.152.90.1
fixed
suse enterprise sap 15 SP7
102.12.0-150200.152.90.1
fixed
suse enterprise server 15
52.7.3-1.35
fixed
suse enterprise server 15 SP1
60.6.2-3.32.1
fixed
suse enterprise server 15 SP2
68.8.0-3.87.1
fixed
suse enterprise server 15 SP3
78.10.0-8.38.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise server 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise server 15 SP6
102.12.0-150200.152.90.1
fixed
suse enterprise server 15 SP7
102.12.0-150200.152.90.1
fixed
MozillaFirefox-translations-common
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise desktop 15 SP1
60.6.2-3.32.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.87.1
fixed
suse enterprise desktop 15 SP3
78.10.0-8.38.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise desktop 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise desktop 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise desktop 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise sap 15 SP1
60.6.2-3.32.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.87.1
fixed
suse enterprise sap 15 SP3
78.10.0-8.38.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise sap 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise sap 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise sap 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 15
52.7.3-1.35
fixed
suse enterprise server 15 SP1
60.6.2-3.32.1
fixed
suse enterprise server 15 SP2
68.8.0-3.87.1
fixed
suse enterprise server 15 SP3
78.10.0-8.38.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise server 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise server 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise server 15 SP7
128.9.0-150200.152.176.1
fixed
MozillaFirefox-translations-other
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise desktop 15 SP1
60.6.2-3.32.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.87.1
fixed
suse enterprise desktop 15 SP3
78.10.0-8.38.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise desktop 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise desktop 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise desktop 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise sap 15 SP1
60.6.2-3.32.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.87.1
fixed
suse enterprise sap 15 SP3
78.10.0-8.38.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise sap 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise sap 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise sap 15 SP7
128.9.0-150200.152.176.1
fixed
suse enterprise server 15
52.7.3-1.35
fixed
suse enterprise server 15 SP1
60.6.2-3.32.1
fixed
suse enterprise server 15 SP2
68.8.0-3.87.1
fixed
suse enterprise server 15 SP3
78.10.0-8.38.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.152.26.1
fixed
suse enterprise server 15 SP5
102.11.0-150200.152.87.1
fixed
suse enterprise server 15 SP6
115.10.0-150200.152.134.1
fixed
suse enterprise server 15 SP7
128.9.0-150200.152.176.1
fixed
MozillaThunderbird
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.80.2
fixed
suse enterprise desktop 15 SP3
78.10.0-8.23.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.80.2
fixed
suse enterprise sap 15 SP3
78.10.0-8.23.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15 SP2
68.8.0-3.80.2
fixed
suse enterprise server 15 SP3
78.10.0-8.23.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15 SP2
68.8.0-3.80.2
fixed
suse enterprise workstation 15 SP3
78.10.0-8.23.1
fixed
suse enterprise workstation 15 SP4
91.8.0-150200.8.65.1
fixed
MozillaThunderbird-devel
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise workstation 15
52.8-1.2
fixed
MozillaThunderbird-translations-common
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.80.2
fixed
suse enterprise desktop 15 SP3
78.10.0-8.23.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.80.2
fixed
suse enterprise sap 15 SP3
78.10.0-8.23.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15 SP2
68.8.0-3.80.2
fixed
suse enterprise server 15 SP3
78.10.0-8.23.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15 SP2
68.8.0-3.80.2
fixed
suse enterprise workstation 15 SP3
78.10.0-8.23.1
fixed
suse enterprise workstation 15 SP4
91.8.0-150200.8.65.1
fixed
MozillaThunderbird-translations-other
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise desktop 15 SP2
68.8.0-3.80.2
fixed
suse enterprise desktop 15 SP3
78.10.0-8.23.1
fixed
suse enterprise desktop 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15 SP2
68.8.0-3.80.2
fixed
suse enterprise sap 15 SP3
78.10.0-8.23.1
fixed
suse enterprise sap 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15 SP2
68.8.0-3.80.2
fixed
suse enterprise server 15 SP3
78.10.0-8.23.1
fixed
suse enterprise server 15 SP4
91.8.0-150200.8.65.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15 SP2
68.8.0-3.80.2
fixed
suse enterprise workstation 15 SP3
78.10.0-8.23.1
fixed
suse enterprise workstation 15 SP4
91.8.0-150200.8.65.1
fixed
at
suse enterprise sap 12 SP1
3.1.14-7.3
fixed
suse enterprise sap 12 SP5
3.1.14-8.6.1
fixed
suse enterprise server 12 SP1
3.1.14-7.3
fixed
suse enterprise server 12 SP5
3.1.14-8.6.1
fixed
flex
suse enterprise sap 12 SP1
2.5.37-8.1
fixed
suse enterprise sap 12 SP5
2.5.37-8.1
fixed
suse enterprise server 12 SP1
2.5.37-8.1
fixed
suse enterprise server 12 SP5
2.5.37-8.1
fixed
flex-32bit
suse enterprise sap 12 SP1
2.5.37-8.1
fixed
suse enterprise sap 12 SP5
2.5.37-8.1
fixed
suse enterprise server 12 SP1
2.5.37-8.1
fixed
suse enterprise server 12 SP5
2.5.37-8.1
fixed
libbonobo
suse enterprise sap 12 SP1
2.32.1-16.1
fixed
suse enterprise sap 12 SP5
2.32.1-16.1
fixed
suse enterprise server 12 SP1
2.32.1-16.1
fixed
suse enterprise server 12 SP5
2.32.1-16.1
fixed
libbonobo-32bit
suse enterprise sap 12 SP1
2.32.1-16.1
fixed
suse enterprise sap 12 SP5
2.32.1-16.1
fixed
suse enterprise server 12 SP1
2.32.1-16.1
fixed
suse enterprise server 12 SP5
2.32.1-16.1
fixed
libbonobo-doc
suse enterprise sap 12 SP1
2.32.1-16.1
fixed
suse enterprise sap 12 SP5
2.32.1-16.1
fixed
suse enterprise server 12 SP1
2.32.1-16.1
fixed
suse enterprise server 12 SP5
2.32.1-16.1
fixed
libbonobo-lang
suse enterprise sap 12 SP1
2.32.1-16.1
fixed
suse enterprise sap 12 SP5
2.32.1-16.1
fixed
suse enterprise server 12 SP1
2.32.1-16.1
fixed
suse enterprise server 12 SP5
2.32.1-16.1
fixed
libkde4
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libkde4-32bit
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libkdecore4
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libkdecore4-32bit
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libksuseinstall1
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libksuseinstall1-32bit
suse enterprise sap 12 SP1
4.12.0-7.3
fixed
suse enterprise sap 12 SP5
4.12.0-10.1
fixed
suse enterprise server 12 SP1
4.12.0-7.3
fixed
suse enterprise server 12 SP5
4.12.0-10.1
fixed
libnetpbm11
suse enterprise sap 12 SP1
10.66.3-4.1
fixed
suse enterprise sap 12 SP5
10.66.3-8.7.2
fixed
suse enterprise server 12 SP1
10.66.3-4.1
fixed
suse enterprise server 12 SP5
10.66.3-8.7.2
fixed
libnetpbm11-32bit
suse enterprise sap 12 SP1
10.66.3-4.1
fixed
suse enterprise sap 12 SP5
10.66.3-8.7.2
fixed
suse enterprise server 12 SP1
10.66.3-4.1
fixed
suse enterprise server 12 SP5
10.66.3-8.7.2
fixed
libwireshark8
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
libwireshark9
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
libwiretap6
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
libwiretap7
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
libwscodecs1
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
libwsutil7
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
libwsutil8
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
netpbm
suse enterprise sap 12 SP1
10.66.3-4.1
fixed
suse enterprise sap 12 SP5
10.66.3-8.7.2
fixed
suse enterprise server 12 SP1
10.66.3-4.1
fixed
suse enterprise server 12 SP5
10.66.3-8.7.2
fixed
openslp
suse enterprise sap 12 SP1
2.0.0-11.1
fixed
suse enterprise sap 12 SP5
2.0.0-18.20.2
fixed
suse enterprise server 12 SP1
2.0.0-11.1
fixed
suse enterprise server 12 SP5
2.0.0-18.20.2
fixed
openslp-32bit
suse enterprise sap 12 SP1
2.0.0-11.1
fixed
suse enterprise sap 12 SP5
2.0.0-18.20.2
fixed
suse enterprise server 12 SP1
2.0.0-11.1
fixed
suse enterprise server 12 SP5
2.0.0-18.20.2
fixed
openslp-server
suse enterprise sap 12 SP1
2.0.0-11.1
fixed
suse enterprise sap 12 SP5
2.0.0-18.20.2
fixed
suse enterprise server 12 SP1
2.0.0-11.1
fixed
suse enterprise server 12 SP5
2.0.0-18.20.2
fixed
perl-Cyrus-IMAP
suse enterprise sap 12 SP1
2.3.18-40.1
fixed
suse enterprise server 12 SP1
2.3.18-40.1
fixed
perl-Cyrus-SIEVE-managesieve
suse enterprise sap 12 SP1
2.3.18-40.1
fixed
suse enterprise server 12 SP1
2.3.18-40.1
fixed
wireshark
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
wireshark-gtk
suse enterprise sap 12 SP1
2.2.6-44.3
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP1
2.2.6-44.3
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed