CVE-2023-46052
- EPSS 0.05%
- Veröffentlicht 27.03.2024 06:15:10
- Zuletzt bearbeitet 23.09.2025 01:01:43
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configu...
CVE-2023-46047
- EPSS 0.04%
- Veröffentlicht 27.03.2024 05:15:47
- Zuletzt bearbeitet 23.09.2025 01:02:34
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controll...
CVE-2020-12862
- EPSS 0.17%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
CVE-2020-12863
- EPSS 0.17%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
CVE-2020-12864
- EPSS 0.19%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
- EPSS 0.3%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
CVE-2020-12866
- EPSS 0.2%
- Veröffentlicht 24.06.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:26
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
CVE-2020-12861
- EPSS 0.53%
- Veröffentlicht 24.06.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:26
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
CVE-2020-12867
- EPSS 0.11%
- Veröffentlicht 01.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:27
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.