Vulnerability Details CVE-2019-16166
                GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.005
                        
                    
                    
                        
                            EPSS Ranking 65.8%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 6.5
                        
                    
                    
                        
                            CVSS v2 Score 4.3
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2019-16166