VYPR

Sane Backends

by Sane

CVEs (10)

  • CVE-2017-6318HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.03

    saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

  • CVE-2023-46052HigMar 27, 2024
    risk 0.46cvss 7.1epss 0.00

    Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

  • CVE-2020-12866MedJun 24, 2020
    risk 0.37cvss 5.7epss 0.01

    A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

  • CVE-2020-12867MedJun 1, 2020
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

  • CVE-2020-12864MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.

  • CVE-2020-12863MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

  • CVE-2020-12862MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

  • CVE-2003-0778Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).

  • CVE-2003-0777Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).

  • CVE-2003-0776Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.