Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-12963

There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-12963
  • Libsass » Libsass » Version: 3.4.5
    cpe:2.3:a:libsass:libsass:3.4.5


Contact Us

Shodan ® - All rights reserved