CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called. | 5.5 |
Medium |
||
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | 9.8 |
Critical |
||
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | 9.8 |
Critical |