libsass kayıtları
libsass üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %36,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read5
- CWE-674 Uncontrolled Recursion3
- CWE-20 Improper Input Validation2
- CWE-772 Missing Release of Resource after Effective Lifetime1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2017-11554İstismar yok | There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5.libsass · libsass · CWE-674 | Yüksek7,5 | — | %1,9 | 22 Tem 2017 |
31İzleyin | CVE-2017-12964İstismar yok | There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp.libsass · libsass · CWE-674 | Yüksek7,5 | — | %1,8 | 18 Ağu 2017 |
31İzleyin | CVE-2017-10687İstismar yok | In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp.libsass · libsass · CWE-125 | Yüksek7,5 | — | %1,8 | 29 Haz 2017 |
31İzleyin | CVE-2017-11341İstismar yok | There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5.libsass · libsass · CWE-125 | Yüksek7,5 | — | %1,7 | 17 Tem 2017 |
30İzleyin | CVE-2017-12963İstismar yok | There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack.libsass · libsass · CWE-125 | Yüksek7,5 | — | %1,2 | 18 Ağu 2017 |
30İzleyin | CVE-2017-12962İstismar yok | There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, llibsass · libsass · CWE-772 | Yüksek7,5 | — | %1,2 | 18 Ağu 2017 |
30İzleyin | CVE-2017-11342İstismar yok | There is an illegal address access in ast.cpp of LibSass 3.4.5.libsass · libsass · CWE-20 | Yüksek7,5 | — | %1,2 | 17 Tem 2017 |
30İzleyin | CVE-2017-11555İstismar yok | There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.libsass · libsass · CWE-20 | Yüksek7,5 | — | %1,2 | 22 Tem 2017 |
30İzleyin | CVE-2017-11556İstismar yok | There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5.libsass · libsass · CWE-674 | Yüksek7,5 | — | %1,2 | 22 Tem 2017 |
26İzleyin | CVE-2017-11605İstismar yok | There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1.libsass · libsass · CWE-125 | Orta6,5 | — | %1,5 | 24 Tem 2017 |
26İzleyin | CVE-2017-11608İstismar yok | There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5.libsass · libsass · CWE-125 | Orta6,5 | — | %1,1 | 24 Tem 2017 |
- CVE-2017-1155431İzleyin
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5.
YüksekCVSS 7,5İstismar yokEPSS %2libsass · libsass22 Tem 2017
- CVE-2017-1296431İzleyin
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp.
YüksekCVSS 7,5İstismar yokEPSS %2libsass · libsass18 Ağu 2017
- CVE-2017-1068731İzleyin
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp.
YüksekCVSS 7,5İstismar yokEPSS %2libsass · libsass29 Haz 2017
- CVE-2017-1134131İzleyin
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5.
YüksekCVSS 7,5İstismar yokEPSS %2libsass · libsass17 Tem 2017
- CVE-2017-1296330İzleyin
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack.
YüksekCVSS 7,5İstismar yokEPSS %1libsass · libsass18 Ağu 2017
- CVE-2017-1296230İzleyin
There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, l
YüksekCVSS 7,5İstismar yokEPSS %1libsass · libsass18 Ağu 2017
- CVE-2017-1134230İzleyin
There is an illegal address access in ast.cpp of LibSass 3.4.5.
YüksekCVSS 7,5İstismar yokEPSS %1libsass · libsass17 Tem 2017
- CVE-2017-1155530İzleyin
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.
YüksekCVSS 7,5İstismar yokEPSS %1libsass · libsass22 Tem 2017
- CVE-2017-1155630İzleyin
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5.
YüksekCVSS 7,5İstismar yokEPSS %1libsass · libsass22 Tem 2017
- CVE-2017-1160526İzleyin
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1.
OrtaCVSS 6,5İstismar yokEPSS %1libsass · libsass24 Tem 2017
- CVE-2017-1160826İzleyin
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5.
OrtaCVSS 6,5İstismar yokEPSS %1libsass · libsass24 Tem 2017