Записи sane-project
9 опубликованных записей вендора sane-project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 77,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read3
- CWE-476 NULL Pointer Dereference2
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2020-12861Эксплойта нет | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to executesane-project · sane backends · CWE-787 | Высокая8,8 | — | 3,0 % | 24 июн. 2020 г. |
32Наблюдать | CVE-2020-12865Эксплойта нет | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execsane-project · sane backends · CWE-787 | Высокая8,0 | — | 1,5 % | 24 июн. 2020 г. |
29Наблюдать | CVE-2023-46047Эксплойта нет | An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function.sane-project · sane backends · CWE-20 | Высокая7,3 | — | 0,4 % | 27 мар. 2024 г. |
28Наблюдать | CVE-2023-46052Эксплойта нет | Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file.sane-project · sane backends | Высокая7,1 | — | 0,4 % | 27 мар. 2024 г. |
22Наблюдать | CVE-2020-12866Эксплойта нет | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to causane-project · sane backends · CWE-476 | Средняя5,7 | — | 1,0 % | 24 июн. 2020 г. |
22Наблюдать | CVE-2020-12867Эксплойта нет | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local netwsane-project · sane backends · CWE-476 | Средняя5,5 | — | 0,5 % | 1 июн. 2020 г. |
17Наблюдать | CVE-2020-12864Эксплойта нет | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Средняя4,3 | — | 1,2 % | 24 июн. 2020 г. |
17Наблюдать | CVE-2020-12862Эксплойта нет | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Средняя4,3 | — | 1,1 % | 24 июн. 2020 г. |
17Наблюдать | CVE-2020-12863Эксплойта нет | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Средняя4,3 | — | 1,0 % | 24 июн. 2020 г. |
- CVE-2020-1286136Наблюдать
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %sane-project · sane backends24 июн. 2020 г.
- CVE-2020-1286532Наблюдать
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to exec
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %sane-project · sane backends24 июн. 2020 г.
- CVE-2023-4604729Наблюдать
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %sane-project · sane backends27 мар. 2024 г.
- CVE-2023-4605228Наблюдать
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %sane-project · sane backends27 мар. 2024 г.
- CVE-2020-1286622Наблюдать
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cau
СредняяCVSS 5,7Эксплойта нетEPSS 1 %sane-project · sane backends24 июн. 2020 г.
- CVE-2020-1286722Наблюдать
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local netw
СредняяCVSS 5,5Эксплойта нетEPSS 0 %sane-project · sane backends1 июн. 2020 г.
- CVE-2020-1286417Наблюдать
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sane-project · sane backends24 июн. 2020 г.
- CVE-2020-1286217Наблюдать
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sane-project · sane backends24 июн. 2020 г.
- CVE-2020-1286317Наблюдать
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sane-project · sane backends24 июн. 2020 г.