Davegamble

Cjson

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 10.09.2026 00:15:08
  • Zuletzt bearbeitet 10.09.2026 20:17:31

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been ma...

  • EPSS 0.26%
  • Veröffentlicht 11.08.2026 21:30:01
  • Zuletzt bearbeitet 24.09.2026 20:30:25

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong obj...

Medienbericht Exploit
  • EPSS 0.25%
  • Veröffentlicht 29.07.2026 13:32:04
  • Zuletzt bearbeitet 04.08.2026 15:03:41

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target...

Medienbericht Exploit
  • EPSS 0.35%
  • Veröffentlicht 29.07.2026 13:32:03
  • Zuletzt bearbeitet 04.08.2026 15:05:11

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponentia...

Medienbericht Exploit
  • EPSS 0.38%
  • Veröffentlicht 29.07.2026 13:32:02
  • Zuletzt bearbeitet 04.08.2026 15:09:26

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operati...

  • EPSS 0.3%
  • Veröffentlicht 27.07.2026 08:40:17
  • Zuletzt bearbeitet 26.08.2026 14:22:00

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more...

Exploit
  • EPSS 0.74%
  • Veröffentlicht 03.09.2025 00:00:00
  • Zuletzt bearbeitet 03.11.2025 19:16:12

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containi...

Exploit
  • EPSS 1.51%
  • Veröffentlicht 14.12.2023 20:15:53
  • Zuletzt bearbeitet 04.11.2025 22:15:55

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

Exploit
  • EPSS 0.96%
  • Veröffentlicht 14.12.2023 20:15:53
  • Zuletzt bearbeitet 22.07.2025 18:17:45

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

Exploit
  • EPSS 2.42%
  • Veröffentlicht 19.07.2019 17:15:11
  • Zuletzt bearbeitet 22.07.2025 18:17:45

DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vecto...