Skip to content
Noroxi

DaveGamble records

14 published records for vendor davegamble.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
85.7%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 23
  4. 25
  5. 26

Bar: total · dark part: CISA KEV.

All records

14 records
  • cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

    CriticalCVSS 9.8No exploitEPSS 3%

    davegamble · cjsonMay 9, 2019

  • cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

    CriticalCVSS 9.8No exploitEPSS 3%

    davegamble · cjsonMay 9, 2019

  • parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and en

    CriticalCVSS 9.8No exploitEPSS 2%

    davegamble · cjsonApr 29, 2019

  • Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible cr

    CriticalCVSS 9.8No exploitEPSS 2%

    davegamble · cjsonAug 20, 2018

  • cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote at

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    davegamble · cjsonSep 3, 2025

  • Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash

    HighCVSS 8.8No exploitEPSS 1%

    davegamble · cjsonAug 20, 2018

  • cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion

    HighCVSS 8.7No exploitEPSS 1%

    davegamble · cjsonJul 29, 2026

  • cJSON cJSON_Compare Exponential Complexity Denial of Service

    HighCVSS 8.2No exploitEPSS 1%

    davegamble · cjsonJul 29, 2026

  • DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions.

    HighCVSS 7.5No exploitEPSS 2%

    davegamble · cjsonJul 19, 2019

  • Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).

    HighCVSS 7.5No exploitEPSS 2%

    davegamble · cjsonAug 20, 2018

  • cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

    HighCVSS 7.5No exploitEPSS 2%

    davegamble · cjsonDec 14, 2023

  • cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

    HighCVSS 7.5No exploitEPSS 1%

    davegamble · cjsonDec 14, 2023

  • cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation

    MediumCVSS 6.9No exploitEPSS 0%

    davegamble · cjsonJul 29, 2026

  • Integer Overflow Leading to Heap Buffer Overflow in cJSON

    MediumCVSS 5.1No exploitEPSS 0%

    davegamble · cjsonJul 27, 2026