Filtered by vendor Sass-lang Subscriptions
Filtered by product Libsass Subscriptions
Total 27 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-18799 1 Sass-lang 1 Libsass 2024-08-05 6.5 Medium
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
CVE-2019-6286 1 Sass-lang 1 Libsass 2024-08-04 N/A
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
CVE-2019-6283 1 Sass-lang 1 Libsass 2024-08-04 6.5 Medium
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
CVE-2019-6284 1 Sass-lang 1 Libsass 2024-08-04 6.5 Medium
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
CVE-2022-43357 1 Sass-lang 2 Libsass, Sassc 2024-08-03 7.5 High
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
CVE-2022-43358 1 Sass-lang 1 Libsass 2024-08-03 7.5 High
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
CVE-2022-26592 1 Sass-lang 1 Libsass 2024-08-03 8.8 High
Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.