Записи DaveGamble
14 опубликованных записей вендора davegamble.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read4
- CWE-476 NULL Pointer Dereference3
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-415 Double Free1
- CWE-416 Use After Free1
- CWE-674 Uncontrolled Recursion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-11835Эксплойта нет | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.davegamble · cjson · CWE-125 | Критическая9,8 | — | 2,6 % | 9 мая 2019 г. |
40В плане | CVE-2019-11834Эксплойта нет | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.davegamble · cjson · CWE-125 | Критическая9,8 | — | 2,5 % | 9 мая 2019 г. |
40В плане | CVE-2016-10749Эксплойта нет | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and endavegamble · cjson · CWE-125 | Критическая9,8 | — | 2,5 % | 29 апр. 2019 г. |
40В плане | CVE-2018-1000217Эксплойта нет | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crdavegamble · cjson · CWE-416 | Критическая9,8 | — | 1,8 % | 20 авг. 2018 г. |
39Наблюдать | CVE-2025-57052Proof of concept | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote atdavegamble · cjson · CWE-125 | Критическая9,8 | — | 0,7 % | 3 сент. 2025 г. |
35Наблюдать | CVE-2018-1000216Эксплойта нет | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crashdavegamble · cjson · CWE-415 | Высокая8,8 | — | 1,5 % | 20 авг. 2018 г. |
34Наблюдать | CVE-2026-67215Эксплойта нет | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustiondavegamble · cjson · CWE-674 | Высокая8,7 | — | 0,7 % | 29 июл. 2026 г. |
32Наблюдать | CVE-2026-67216Эксплойта нет | cJSON cJSON_Compare Exponential Complexity Denial of Servicedavegamble · cjson · CWE-407 | Высокая8,2 | — | 0,6 % | 29 июл. 2026 г. |
31Наблюдать | CVE-2019-1010239Эксплойта нет | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions.davegamble · cjson · CWE-476 | Высокая7,5 | — | 2,4 % | 19 июл. 2019 г. |
31Наблюдать | CVE-2018-1000215Эксплойта нет | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).davegamble · cjson · CWE-772 | Высокая7,5 | — | 1,7 % | 20 авг. 2018 г. |
30Наблюдать | CVE-2023-50471Эксплойта нет | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.davegamble · cjson · CWE-476 | Высокая7,5 | — | 1,5 % | 14 дек. 2023 г. |
30Наблюдать | CVE-2023-50472Эксплойта нет | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.davegamble · cjson · CWE-476 | Высокая7,5 | — | 1,0 % | 14 дек. 2023 г. |
27Наблюдать | CVE-2026-67217Эксплойта нет | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validationdavegamble · cjson · CWE-696 | Средняя6,9 | — | 0,4 % | 29 июл. 2026 г. |
20Наблюдать | CVE-2026-16554Эксплойта нет | Integer Overflow Leading to Heap Buffer Overflow in cJSONdavegamble · cjson · CWE-190 | Средняя5,1 | — | 0,3 % | 27 июл. 2026 г. |
- CVE-2019-1183540В плане
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %davegamble · cjson9 мая 2019 г.
- CVE-2019-1183440В плане
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %davegamble · cjson9 мая 2019 г.
- CVE-2016-1074940В плане
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and en
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %davegamble · cjson29 апр. 2019 г.
- CVE-2018-100021740В плане
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible cr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %davegamble · cjson20 авг. 2018 г.
- CVE-2025-5705239Наблюдать
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote at
КритическаяCVSS 9,8Proof of conceptEPSS 1 %davegamble · cjson3 сент. 2025 г.
- CVE-2018-100021635Наблюдать
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %davegamble · cjson20 авг. 2018 г.
- CVE-2026-6721534Наблюдать
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %davegamble · cjson29 июл. 2026 г.
- CVE-2026-6721632Наблюдать
cJSON cJSON_Compare Exponential Complexity Denial of Service
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %davegamble · cjson29 июл. 2026 г.
- CVE-2019-101023931Наблюдать
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %davegamble · cjson19 июл. 2019 г.
- CVE-2018-100021531Наблюдать
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %davegamble · cjson20 авг. 2018 г.
- CVE-2023-5047130Наблюдать
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %davegamble · cjson14 дек. 2023 г.
- CVE-2023-5047230Наблюдать
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %davegamble · cjson14 дек. 2023 г.
- CVE-2026-6721727Наблюдать
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
СредняяCVSS 6,9Эксплойта нетEPSS 0 %davegamble · cjson29 июл. 2026 г.
- CVE-2026-1655420Наблюдать
Integer Overflow Leading to Heap Buffer Overflow in cJSON
СредняяCVSS 5,1Эксплойта нетEPSS 0 %davegamble · cjson27 июл. 2026 г.