VYPR

Sane

by Sane

CVEs (14)

  • CVE-2023-46047Mar 27, 2024
    risk 0.00cvss epss 0.00

    An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

  • CVE-2023-46052Mar 27, 2024
    risk 0.00cvss epss 0.00

    Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

  • CVE-2020-12862Jun 24, 2020
    risk 0.00cvss epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

  • CVE-2020-12865Jun 24, 2020
    risk 0.00cvss epss 0.01

    A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.

  • CVE-2020-12866Jun 24, 2020
    risk 0.00cvss epss 0.01

    A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

  • CVE-2020-12861Jun 24, 2020
    risk 0.00cvss epss 0.03

    A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.

  • CVE-2003-0775Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).

  • CVE-2003-0777Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).

  • CVE-2003-0774Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.

  • CVE-2003-0776Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.

  • CVE-2003-0778Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).

  • CVE-2003-0773Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

  • CVE-2001-0890Dec 11, 2001
    risk 0.00cvss epss 0.00

    Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.

  • CVE-2001-1360Jul 19, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.