sane CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

sane vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to sane, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2003-0778 saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption). [email protected] 5.0 0.83% 2003-09-22 2026-04-16
CVE-2003-0777 saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault). [email protected] 5.0 0.83% 2003-09-22 2026-04-16
CVE-2003-0776 saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences. [email protected] 7.5 0.74% 2003-09-22 2026-04-16
CVE-2003-0775 saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash). [email protected] 5.0 1.58% 2003-09-22 2026-04-16
CVE-2003-0774 saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed. [email protected] 7.5 1.50% 2003-09-22 2026-04-16
CVE-2003-0773 saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf. [email protected] 7.5 1.27% 2003-09-22 2026-04-16
CVE-2001-0890 Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files. [email protected] 2.1 0.09% 2001-12-11 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence