Sane
by Sane
CVEs (14)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46047 | 0.00 | — | 0.00 | Mar 27, 2024 | An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file. | |||
| CVE-2023-46052 | 0.00 | — | 0.00 | Mar 27, 2024 | Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file. | |||
| CVE-2020-12862 | 0.00 | — | 0.01 | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082. | |||
| CVE-2020-12865 | 0.00 | — | 0.01 | Jun 24, 2020 | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. | |||
| CVE-2020-12866 | 0.00 | — | 0.01 | Jun 24, 2020 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. | |||
| CVE-2020-12861 | 0.00 | — | 0.03 | Jun 24, 2020 | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. | |||
| CVE-2003-0775 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash). | |||
| CVE-2003-0777 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault). | |||
| CVE-2003-0774 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed. | |||
| CVE-2003-0776 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences. | |||
| CVE-2003-0778 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption). | |||
| CVE-2003-0773 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf. | |||
| CVE-2001-0890 | 0.00 | — | 0.00 | Dec 11, 2001 | Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files. | |||
| CVE-2001-1360 | 0.00 | — | 0.00 | Jul 19, 2001 | Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned. |
- CVE-2023-46047Mar 27, 2024risk 0.00cvss —epss 0.00
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.
- CVE-2023-46052Mar 27, 2024risk 0.00cvss —epss 0.00
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.
- CVE-2020-12862Jun 24, 2020risk 0.00cvss —epss 0.01
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
- CVE-2020-12865Jun 24, 2020risk 0.00cvss —epss 0.01
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
- CVE-2020-12866Jun 24, 2020risk 0.00cvss —epss 0.01
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
- CVE-2020-12861Jun 24, 2020risk 0.00cvss —epss 0.03
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
- CVE-2003-0775Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).
- CVE-2003-0777Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).
- CVE-2003-0774Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
- CVE-2003-0776Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
- CVE-2003-0778Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).
- CVE-2003-0773Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
- CVE-2001-0890Dec 11, 2001risk 0.00cvss —epss 0.00
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
- CVE-2001-1360Jul 19, 2001risk 0.00cvss —epss 0.00
Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.