Skip to main content

Vendor/product archive

cjson_project / cjson CVEs

Beta · best-effort

3 CVEs tagged to cjson_project / cjson0 Critical, 1 High, 0 Medium, 2 Low, 0 Unrated.

CVE-2023-53154

Published May 23, 2025

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26819

Published Apr 19, 2025

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-31755

Published Apr 26, 2024

cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1