Davegamble
Davegamble Cjson: vulnerabilidades y CVE
Davegamble Cjson tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87933 | Media (5.5) | 0.53% | — | 10 sept 2026 | A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched… |
| CVE-2026-67217 | Media (6.9) | 0.43% | — | 29 jul 2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot… |
| CVE-2026-67216 | Alta (8.2) | 0.65% | — | 29 jul 2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard,… |
| CVE-2026-67215 | Alta (8.7) | 0.70% | — | 29 jul 2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch… |
| CVE-2026-16554 | Media (5.1) | 0.29% | — | 27 jul 2026 | cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing… |
| CVE-2025-57052 | Crítica (9.8) | 0.74% | — | 3 sept 2025 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via… |
| CVE-2023-50472 | Alta (7.5) | 0.97% | — | 14 dic 2023 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. |
| CVE-2023-50471 | Alta (7.5) | 1.5% | — | 14 dic 2023 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. |
| CVE-2019-1010239 | Alta (7.5) | 2.4% | — | 19 jul 2019 | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is:… |
| CVE-2019-11835 | Crítica (9.8) | 2.6% | — | 9 may 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. |
| CVE-2019-11834 | Crítica (9.8) | 2.5% | — | 9 may 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. |
| CVE-2016-10749 | Crítica (9.8) | 2.5% | — | 29 abr 2019 | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character. |
| CVE-2018-1000217 | Crítica (9.8) | 1.8% | — | 20 ago 2018 | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via… |
| CVE-2018-1000216 | Alta (8.8) | 1.5% | — | 20 ago 2018 | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to… |
| CVE-2018-1000215 | Alta (7.5) | 1.7% | — | 20 ago 2018 | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be… |