Vulnerabilities > Sass Lang > Libsass > 3.6.0

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-18799 NULL Pointer Dereference vulnerability in Sass-Lang Libsass
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
network
sass-lang CWE-476
4.3
2019-11-06 CVE-2019-18798 Out-of-bounds Read vulnerability in Sass-Lang Libsass
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
network
sass-lang CWE-125
4.3
2019-11-06 CVE-2019-18797 Uncontrolled Recursion vulnerability in Sass-Lang Libsass
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
network
sass-lang CWE-674
4.3