Search CVE reports
1 – 10 of 10 results
CVE-2023-46052
Negligible priority** DISPUTED ** Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed...
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2023-46047
Negligible priority** DISPUTED ** An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be...
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2020-12866
Medium prioritySome fixes available 2 of 3
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Not affected |
CVE-2020-12865
Medium prioritySome fixes available 3 of 4
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Fixed |
CVE-2020-12864
Low prioritySome fixes available 2 of 3
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Not affected |
CVE-2020-12863
Low prioritySome fixes available 3 of 4
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Fixed |
CVE-2020-12862
Low prioritySome fixes available 3 of 4
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Fixed |
CVE-2020-12861
Medium prioritySome fixes available 2 of 3
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Not affected |
CVE-2020-12867
Medium prioritySome fixes available 3 of 4
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Fixed | Fixed | Fixed |
CVE-2017-6318
Low prioritySome fixes available 1 of 5
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
1 affected packages
sane-backends
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
sane-backends | — | — | Not affected | Not affected | Fixed |