CVE-2024-21525
All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new twain.TwainSDK with a productName or productFamily, manufacturer, version.info property of length >= 34 chars leads to a buffer overflow vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:P
- EPSS probability
- 0.55%
- CWE
- CWE-703
- Published
- 2024-07-10
- Last modified
- 2026-03-13
Affected products
- n/a node-twain
Weakness type
Related vulnerabilities
- CVE-2023-0397 — DoS: Invalid Initialization in le_read_buffer_size_complete
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2021-23859 — Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products
- CVE-2019-5031 — An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2026-20329 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities