DaveGamble records
14 published records for vendor davegamble.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read4
- CWE-476 NULL Pointer Dereference3
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-415 Double Free1
- CWE-416 Use After Free1
- CWE-674 Uncontrolled Recursion1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-11835No exploit | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.davegamble · cjson · CWE-125 | Critical9.8 | — | 2.6% | May 9, 2019 |
40Plan | CVE-2019-11834No exploit | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.davegamble · cjson · CWE-125 | Critical9.8 | — | 2.5% | May 9, 2019 |
40Plan | CVE-2016-10749No exploit | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and endavegamble · cjson · CWE-125 | Critical9.8 | — | 2.5% | Apr 29, 2019 |
40Plan | CVE-2018-1000217No exploit | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crdavegamble · cjson · CWE-416 | Critical9.8 | — | 1.8% | Aug 20, 2018 |
39Monitor | CVE-2025-57052Proof of concept | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote atdavegamble · cjson · CWE-125 | Critical9.8 | — | 0.7% | Sep 3, 2025 |
35Monitor | CVE-2018-1000216No exploit | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crashdavegamble · cjson · CWE-415 | High8.8 | — | 1.5% | Aug 20, 2018 |
34Monitor | CVE-2026-67215No exploit | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustiondavegamble · cjson · CWE-674 | High8.7 | — | 0.7% | Jul 29, 2026 |
32Monitor | CVE-2026-67216No exploit | cJSON cJSON_Compare Exponential Complexity Denial of Servicedavegamble · cjson · CWE-407 | High8.2 | — | 0.6% | Jul 29, 2026 |
31Monitor | CVE-2019-1010239No exploit | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions.davegamble · cjson · CWE-476 | High7.5 | — | 2.4% | Jul 19, 2019 |
31Monitor | CVE-2018-1000215No exploit | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).davegamble · cjson · CWE-772 | High7.5 | — | 1.7% | Aug 20, 2018 |
30Monitor | CVE-2023-50471No exploit | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.davegamble · cjson · CWE-476 | High7.5 | — | 1.5% | Dec 14, 2023 |
30Monitor | CVE-2023-50472No exploit | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.davegamble · cjson · CWE-476 | High7.5 | — | 1.0% | Dec 14, 2023 |
27Monitor | CVE-2026-67217No exploit | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validationdavegamble · cjson · CWE-696 | Medium6.9 | — | 0.4% | Jul 29, 2026 |
20Monitor | CVE-2026-16554No exploit | Integer Overflow Leading to Heap Buffer Overflow in cJSONdavegamble · cjson · CWE-190 | Medium5.1 | — | 0.3% | Jul 27, 2026 |
- CVE-2019-1183540Plan
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CriticalCVSS 9.8No exploitEPSS 3%davegamble · cjsonMay 9, 2019
- CVE-2019-1183440Plan
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
CriticalCVSS 9.8No exploitEPSS 3%davegamble · cjsonMay 9, 2019
- CVE-2016-1074940Plan
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and en
CriticalCVSS 9.8No exploitEPSS 2%davegamble · cjsonApr 29, 2019
- CVE-2018-100021740Plan
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible cr
CriticalCVSS 9.8No exploitEPSS 2%davegamble · cjsonAug 20, 2018
- CVE-2025-5705239Monitor
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote at
CriticalCVSS 9.8Proof of conceptEPSS 1%davegamble · cjsonSep 3, 2025
- CVE-2018-100021635Monitor
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash
HighCVSS 8.8No exploitEPSS 1%davegamble · cjsonAug 20, 2018
- CVE-2026-6721534Monitor
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
HighCVSS 8.7No exploitEPSS 1%davegamble · cjsonJul 29, 2026
- CVE-2026-6721632Monitor
cJSON cJSON_Compare Exponential Complexity Denial of Service
HighCVSS 8.2No exploitEPSS 1%davegamble · cjsonJul 29, 2026
- CVE-2019-101023931Monitor
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions.
HighCVSS 7.5No exploitEPSS 2%davegamble · cjsonJul 19, 2019
- CVE-2018-100021531Monitor
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).
HighCVSS 7.5No exploitEPSS 2%davegamble · cjsonAug 20, 2018
- CVE-2023-5047130Monitor
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
HighCVSS 7.5No exploitEPSS 2%davegamble · cjsonDec 14, 2023
- CVE-2023-5047230Monitor
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
HighCVSS 7.5No exploitEPSS 1%davegamble · cjsonDec 14, 2023
- CVE-2026-6721727Monitor
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
MediumCVSS 6.9No exploitEPSS 0%davegamble · cjsonJul 29, 2026
- CVE-2026-1655420Monitor
Integer Overflow Leading to Heap Buffer Overflow in cJSON
MediumCVSS 5.1No exploitEPSS 0%davegamble · cjsonJul 27, 2026