VYPR
Vendor

Sane

Products
2
CVEs
8
Across products
14
Status
Private

Products

2

Recent CVEs

8
  • CVE-2003-0775Sep 22, 2003
    risk 0.00cvss epss 0.02

    saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).

  • CVE-2003-0776Sep 22, 2003
    risk 0.00cvss epss 0.01

    saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.

  • CVE-2003-0778Sep 22, 2003
    risk 0.00cvss epss 0.01

    saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).

  • CVE-2003-0774Sep 22, 2003
    risk 0.00cvss epss 0.01

    saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.

  • CVE-2003-0773Sep 22, 2003
    risk 0.00cvss epss 0.01

    saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

  • CVE-2003-0777Sep 22, 2003
    risk 0.00cvss epss 0.01

    saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).

  • CVE-2001-0890Dec 11, 2001
    risk 0.00cvss epss 0.00

    Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.

  • CVE-2001-1360Jul 19, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.