CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

sane-project

sane_backends

9 known vulnerabilities · sorted by CVSS score

CVE-2020-12861
HIGH8.8

A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.

sane-project / sane_backends+5
Adjacent
Published Jun 24, 2020
CVE-2020-12865
HIGH8.0

A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.

sane-project / sane_backends+6
Adjacent
Published Jun 24, 2020
CVE-2023-46047
HIGH7.3

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

sane-project / sane_backends
Local
Published Mar 27, 2024
CVE-2023-46052
HIGH7.1

Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

sane-project / sane_backends
Local
Published Mar 27, 2024
CVE-2020-12866
MEDIUM5.7

A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

sane-project / sane_backends+5
Adjacent
Published Jun 24, 2020
CVE-2020-12867
MEDIUM5.5

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

sane-project / sane_backends+7
Local
Published Jun 1, 2020
CVE-2020-12864
MEDIUM4.3

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.

sane-project / sane_backends+5
Adjacent
Published Jun 24, 2020
CVE-2020-12862
MEDIUM4.3

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

sane-project / sane_backends+6
Adjacent
Published Jun 24, 2020
CVE-2020-12863
MEDIUM4.3

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

sane-project / sane_backends+6
Adjacent
Published Jun 24, 2020