Davegamble

Cjson

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Published 03.09.2025 00:00:00
  • Last modified 08.09.2025 17:37:25

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containi...

Exploit
  • EPSS 0.12%
  • Published 14.12.2023 20:15:53
  • Last modified 22.07.2025 18:17:45

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

Exploit
  • EPSS 0.1%
  • Published 14.12.2023 20:15:53
  • Last modified 22.07.2025 18:17:45

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

Exploit
  • EPSS 0.47%
  • Published 19.07.2019 17:15:11
  • Last modified 22.07.2025 18:17:45

DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vecto...

Exploit
  • EPSS 0.62%
  • Published 09.05.2019 05:29:02
  • Last modified 22.07.2025 18:17:45

cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

Exploit
  • EPSS 0.67%
  • Published 09.05.2019 05:29:02
  • Last modified 22.07.2025 18:17:45

cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

Exploit
  • EPSS 0.57%
  • Published 29.04.2019 14:29:00
  • Last modified 22.07.2025 18:17:45

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

  • EPSS 0.68%
  • Published 20.08.2018 20:29:00
  • Last modified 22.07.2025 18:17:45

Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in l...

Exploit
  • EPSS 0.4%
  • Published 20.08.2018 20:29:00
  • Last modified 22.07.2025 18:17:45

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, de...

Exploit
  • EPSS 0.51%
  • Published 20.08.2018 20:29:00
  • Last modified 22.07.2025 18:17:45

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses ...