Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2021-27568
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
0
Attacker Value
Unknown
CVE-2020-7712
Disclosure Date: August 30, 2020 (last updated February 22, 2025)
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
0
Attacker Value
Unknown
CVE-2020-12762
Disclosure Date: May 09, 2020 (last updated February 21, 2025)
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
0
Attacker Value
Unknown
keystone_json_assignment backend granted access to any project for users in use…
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
0
Attacker Value
Unknown
CVE-2019-1010239
Disclosure Date: July 19, 2019 (last updated November 27, 2024)
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
0
Attacker Value
Unknown
CVE-2019-11835
Disclosure Date: May 09, 2019 (last updated November 27, 2024)
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
0
Attacker Value
Unknown
CVE-2019-11834
Disclosure Date: May 09, 2019 (last updated November 27, 2024)
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
0
Attacker Value
Unknown
CVE-2016-10749
Disclosure Date: April 29, 2019 (last updated November 27, 2024)
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
0
Attacker Value
Unknown
CVE-2018-14632
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
0
Attacker Value
Unknown
CVE-2018-1000216
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.
0