VYPR

Sane Backends

by Sane Project

CVEs (9)

  • CVE-2020-12861HigJun 24, 2020
    risk 0.57cvss 8.8epss 0.03

    A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.

  • CVE-2020-12865HigJun 24, 2020
    risk 0.52cvss 8.0epss 0.01

    A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.

  • CVE-2023-46047HigMar 27, 2024
    risk 0.47cvss 7.3epss 0.00

    An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

  • CVE-2023-46052HigMar 27, 2024
    risk 0.46cvss 7.1epss 0.00

    Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

  • CVE-2020-12866MedJun 24, 2020
    risk 0.37cvss 5.7epss 0.01

    A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

  • CVE-2020-12867MedJun 1, 2020
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

  • CVE-2020-12864MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.

  • CVE-2020-12863MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

  • CVE-2020-12862MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.