libsass records
11 published records for vendor libsass.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 36.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read5
- CWE-674 Uncontrolled Recursion3
- CWE-20 Improper Input Validation2
- CWE-772 Missing Release of Resource after Effective Lifetime1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2017-11554No exploit | There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5.libsass · libsass · CWE-674 | High7.5 | — | 1.9% | Jul 22, 2017 |
31Monitor | CVE-2017-12964No exploit | There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp.libsass · libsass · CWE-674 | High7.5 | — | 1.8% | Aug 18, 2017 |
31Monitor | CVE-2017-10687No exploit | In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp.libsass · libsass · CWE-125 | High7.5 | — | 1.8% | Jun 29, 2017 |
31Monitor | CVE-2017-11341No exploit | There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5.libsass · libsass · CWE-125 | High7.5 | — | 1.7% | Jul 17, 2017 |
30Monitor | CVE-2017-12963No exploit | There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack.libsass · libsass · CWE-125 | High7.5 | — | 1.2% | Aug 18, 2017 |
30Monitor | CVE-2017-12962No exploit | There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, llibsass · libsass · CWE-772 | High7.5 | — | 1.2% | Aug 18, 2017 |
30Monitor | CVE-2017-11342No exploit | There is an illegal address access in ast.cpp of LibSass 3.4.5.libsass · libsass · CWE-20 | High7.5 | — | 1.2% | Jul 17, 2017 |
30Monitor | CVE-2017-11555No exploit | There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.libsass · libsass · CWE-20 | High7.5 | — | 1.2% | Jul 22, 2017 |
30Monitor | CVE-2017-11556No exploit | There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5.libsass · libsass · CWE-674 | High7.5 | — | 1.2% | Jul 22, 2017 |
26Monitor | CVE-2017-11605No exploit | There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1.libsass · libsass · CWE-125 | Medium6.5 | — | 1.5% | Jul 24, 2017 |
26Monitor | CVE-2017-11608No exploit | There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5.libsass · libsass · CWE-125 | Medium6.5 | — | 1.1% | Jul 24, 2017 |
- CVE-2017-1155431Monitor
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5.
HighCVSS 7.5No exploitEPSS 2%libsass · libsassJul 22, 2017
- CVE-2017-1296431Monitor
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp.
HighCVSS 7.5No exploitEPSS 2%libsass · libsassAug 18, 2017
- CVE-2017-1068731Monitor
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp.
HighCVSS 7.5No exploitEPSS 2%libsass · libsassJun 29, 2017
- CVE-2017-1134131Monitor
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5.
HighCVSS 7.5No exploitEPSS 2%libsass · libsassJul 17, 2017
- CVE-2017-1296330Monitor
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack.
HighCVSS 7.5No exploitEPSS 1%libsass · libsassAug 18, 2017
- CVE-2017-1296230Monitor
There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, l
HighCVSS 7.5No exploitEPSS 1%libsass · libsassAug 18, 2017
- CVE-2017-1134230Monitor
There is an illegal address access in ast.cpp of LibSass 3.4.5.
HighCVSS 7.5No exploitEPSS 1%libsass · libsassJul 17, 2017
- CVE-2017-1155530Monitor
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.
HighCVSS 7.5No exploitEPSS 1%libsass · libsassJul 22, 2017
- CVE-2017-1155630Monitor
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5.
HighCVSS 7.5No exploitEPSS 1%libsass · libsassJul 22, 2017
- CVE-2017-1160526Monitor
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1.
MediumCVSS 6.5No exploitEPSS 1%libsass · libsassJul 24, 2017
- CVE-2017-1160826Monitor
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5.
MediumCVSS 6.5No exploitEPSS 1%libsass · libsassJul 24, 2017