Lucene search

K

Sane Security Vulnerabilities

cve
cve

CVE-2020-12867

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka...

5.5CVSS

5.4AI Score

0.001EPSS

2020-06-01 02:15 PM
231
2
cve
cve

CVE-2020-12861

A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka...

8.8CVSS

8.7AI Score

0.007EPSS

2020-06-24 01:15 PM
163
cve
cve

CVE-2020-12866

A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service,...

5.7CVSS

6.4AI Score

0.001EPSS

2020-06-24 01:15 PM
144
cve
cve

CVE-2020-12862

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka...

4.3CVSS

5.7AI Score

0.001EPSS

2020-06-24 01:15 PM
144
3
cve
cve

CVE-2020-12863

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka...

4.3CVSS

5.7AI Score

0.001EPSS

2020-06-24 01:15 PM
146
2
cve
cve

CVE-2020-12865

A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka...

8CVSS

8.3AI Score

0.0005EPSS

2020-06-24 01:15 PM
162
2
cve
cve

CVE-2020-12864

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka...

4.3CVSS

5.7AI Score

0.001EPSS

2020-06-24 01:15 PM
142
cve
cve

CVE-2017-6318

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION...

7.5CVSS

5.8AI Score

0.003EPSS

2017-03-20 04:59 PM
49
cve
cve

CVE-2003-0776

saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown...

6.2AI Score

0.007EPSS

2003-09-22 04:00 AM
29
cve
cve

CVE-2003-0774

saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is...

6.2AI Score

0.02EPSS

2003-09-22 04:00 AM
22
cve
cve

CVE-2003-0777

saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation...

6.1AI Score

0.005EPSS

2003-09-22 04:00 AM
25
cve
cve

CVE-2003-0775

saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or...

6.5AI Score

0.026EPSS

2003-09-22 04:00 AM
22
cve
cve

CVE-2003-0778

saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory...

6.2AI Score

0.009EPSS

2003-09-22 04:00 AM
25
cve
cve

CVE-2003-0773

saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in...

6.2AI Score

0.013EPSS

2003-09-22 04:00 AM
24
cve
cve

CVE-2001-0890

Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary...

6.6AI Score

0.0004EPSS

2002-07-23 04:00 AM
25