Vulnerabilities > Cjson Project > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-05-09 CVE-2019-11835 Out-of-bounds Write vulnerability in multiple products
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
network
low complexity
cjson-project oracle CWE-787
critical
9.8
2019-05-09 CVE-2019-11834 Out-of-bounds Write vulnerability in multiple products
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
network
low complexity
cjson-project oracle CWE-787
critical
9.8
2019-04-29 CVE-2016-10749 Out-of-bounds Read vulnerability in Cjson Project Cjson
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
network
low complexity
cjson-project CWE-125
critical
9.8
2018-08-20 CVE-2018-1000217 Use After Free vulnerability in Cjson Project Cjson
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE.
network
low complexity
cjson-project CWE-416
critical
9.8