CVE-2014-9157 on Ubuntu 14.04 LTS (trusty) - medium.
Description:
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.