Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-12964 | There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2017-11605 +1 in the same advisory: …11608 | There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2017-11554 | There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2017-11341 +1 in the same advisory: …11342 | There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2017-10687 | In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack. NVD description · AI analysis pending | 7.5 | 2% |
| — |