CVE-2025-57052
- EPSS 0.1%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 08.09.2025 17:37:25
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containi...
CVE-2023-50471
- EPSS 0.12%
- Veröffentlicht 14.12.2023 20:15:53
- Zuletzt bearbeitet 22.07.2025 18:17:45
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
CVE-2023-50472
- EPSS 0.1%
- Veröffentlicht 14.12.2023 20:15:53
- Zuletzt bearbeitet 22.07.2025 18:17:45
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
CVE-2019-1010239
- EPSS 0.47%
- Veröffentlicht 19.07.2019 17:15:11
- Zuletzt bearbeitet 22.07.2025 18:17:45
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vecto...
CVE-2019-11834
- EPSS 0.62%
- Veröffentlicht 09.05.2019 05:29:02
- Zuletzt bearbeitet 22.07.2025 18:17:45
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
CVE-2019-11835
- EPSS 0.67%
- Veröffentlicht 09.05.2019 05:29:02
- Zuletzt bearbeitet 22.07.2025 18:17:45
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CVE-2016-10749
- EPSS 0.57%
- Veröffentlicht 29.04.2019 14:29:00
- Zuletzt bearbeitet 22.07.2025 18:17:45
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
CVE-2018-1000215
- EPSS 0.68%
- Veröffentlicht 20.08.2018 20:29:00
- Zuletzt bearbeitet 22.07.2025 18:17:45
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in l...
CVE-2018-1000216
- EPSS 0.4%
- Veröffentlicht 20.08.2018 20:29:00
- Zuletzt bearbeitet 22.07.2025 18:17:45
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, de...
CVE-2018-1000217
- EPSS 0.51%
- Veröffentlicht 20.08.2018 20:29:00
- Zuletzt bearbeitet 22.07.2025 18:17:45
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses ...