Vulnerabilities
Vulnerable Software
Sass-Lang:  >> Libsass  >> 2.1.0  Security Vulnerabilities
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-11-06
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-11-06
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-11-06
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
CVSS Score
6.5
EPSS Score
0.011
Published
2019-04-23
In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, because of certain incorrect parsing of '%' as a modulo operator in parser.cpp.
CVSS Score
6.5
EPSS Score
0.007
Published
2018-12-04
In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, as demonstrated by recursive calls involving clone(), cloneChildren(), and copy().
CVSS Score
6.5
EPSS Score
0.005
Published
2018-12-04
In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-12-04
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
CVSS Score
8.1
EPSS Score
0.004
Published
2018-06-04
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Score
8.8
EPSS Score
0.005
Published
2018-06-04
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-06-04


Contact Us

Shodan ® - All rights reserved