sane-project records
9 published records for vendor sane-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 77.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read3
- CWE-476 NULL Pointer Dereference2
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2020-12861No exploit | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to executesane-project · sane backends · CWE-787 | High8.8 | — | 3.0% | Jun 24, 2020 |
32Monitor | CVE-2020-12865No exploit | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execsane-project · sane backends · CWE-787 | High8.0 | — | 1.5% | Jun 24, 2020 |
29Monitor | CVE-2023-46047No exploit | An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function.sane-project · sane backends · CWE-20 | High7.3 | — | 0.4% | Mar 27, 2024 |
28Monitor | CVE-2023-46052No exploit | Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file.sane-project · sane backends | High7.1 | — | 0.4% | Mar 27, 2024 |
22Monitor | CVE-2020-12866No exploit | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to causane-project · sane backends · CWE-476 | Medium5.7 | — | 1.0% | Jun 24, 2020 |
22Monitor | CVE-2020-12867No exploit | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local netwsane-project · sane backends · CWE-476 | Medium5.5 | — | 0.5% | Jun 1, 2020 |
17Monitor | CVE-2020-12864No exploit | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Medium4.3 | — | 1.2% | Jun 24, 2020 |
17Monitor | CVE-2020-12862No exploit | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Medium4.3 | — | 1.1% | Jun 24, 2020 |
17Monitor | CVE-2020-12863No exploit | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read sane-project · sane backends · CWE-125 | Medium4.3 | — | 1.0% | Jun 24, 2020 |
- CVE-2020-1286136Monitor
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute
HighCVSS 8.8No exploitEPSS 3%sane-project · sane backendsJun 24, 2020
- CVE-2020-1286532Monitor
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to exec
HighCVSS 8.0No exploitEPSS 1%sane-project · sane backendsJun 24, 2020
- CVE-2023-4604729Monitor
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function.
HighCVSS 7.3No exploitEPSS 0%sane-project · sane backendsMar 27, 2024
- CVE-2023-4605228Monitor
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file.
HighCVSS 7.1No exploitEPSS 0%sane-project · sane backendsMar 27, 2024
- CVE-2020-1286622Monitor
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cau
MediumCVSS 5.7No exploitEPSS 1%sane-project · sane backendsJun 24, 2020
- CVE-2020-1286722Monitor
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local netw
MediumCVSS 5.5No exploitEPSS 0%sane-project · sane backendsJun 1, 2020
- CVE-2020-1286417Monitor
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
MediumCVSS 4.3No exploitEPSS 1%sane-project · sane backendsJun 24, 2020
- CVE-2020-1286217Monitor
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
MediumCVSS 4.3No exploitEPSS 1%sane-project · sane backendsJun 24, 2020
- CVE-2020-1286317Monitor
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read
MediumCVSS 4.3No exploitEPSS 1%sane-project · sane backendsJun 24, 2020