Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.36%—Sane-project Sane Backends27/3/202417/6/2026
Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.
ModificadaAlta (7.3)0.37%—Sane-project Sane Backends27/3/202417/6/2026
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.
ModificadaMedia (5.7)1.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
ModificadaAlta (8)1.5%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
ModificadaMedia (4.3)1.2%—Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
ModificadaMedia (4.3)1.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
ModificadaMedia (4.3)1.1%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
ModificadaAlta (8.8)3.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
ModificadaMedia (5.5)0.50%—Sane-project Sane BackendsFedoraproject FedoraDebian LinuxOpensuse Leap+11/6/202017/6/2026
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
ModificadaAlta (7.5)3.0%—Opensuse LeapSane-backends Project Sane-backends20/3/201717/6/2026
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.