Sass-Lang Libsass vulnerabilities
27 known vulnerabilities affecting sass-lang/libsass.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2018-11697HIGHCVSS 8.1≤ 3.5.42018-06-04
CVE-2018-11697 [HIGH] CWE-125 CVE-2018-11697: An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
nvd
CVE-2018-11694HIGHCVSS 8.8≤ 3.5.42018-06-04
CVE-2018-11694 [HIGH] CWE-476 CVE-2018-11694: An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the functi
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2018-11696HIGHCVSS 8.8≤ 3.5.42018-06-04
CVE-2018-11696 [HIGH] CWE-476 CVE-2018-11696: An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the functi
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2018-11698HIGHCVSS 8.1≤ 3.5.42018-06-04
CVE-2018-11698 [HIGH] CWE-125 CVE-2018-11698: An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
nvd
CVE-2018-11693HIGHCVSS 8.1≤ 3.5.42018-06-04
CVE-2018-11693 [HIGH] CWE-125 CVE-2018-11693: An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
nvd
CVE-2018-11695HIGHCVSS 8.8≤ 3.5.22018-06-04
CVE-2018-11695 [HIGH] CWE-476 CVE-2018-11695: An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2018-11499CRITICALCVSS 9.8≥ 3.4.0, ≤ 3.5.42018-05-26
CVE-2018-11499 [CRITICAL] CWE-416 CVE-2018-11499: A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5
A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.
nvd
← Previous2 / 2