jqlang kayıtları
jqlang üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-674 Uncontrolled Recursion5
- CWE-190 Integer Overflow or Wraparound4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-125 Out-of-bounds Read2
- CWE-20 Improper Input Validation2
- CWE-787 Out-of-bounds Write2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2024-53427İstismar yok | decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-jqlang · jq · CWE-843 | Yüksek8,1 | — | %0,4 | 26 Şub 2025 |
30İzleyin | CVE-2023-49355İstismar yok | decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input.jqlang · jq · CWE-787 | Yüksek7,5 | — | %1,2 | 11 Ara 2023 |
30İzleyin | CVE-2025-48060Kavram kanıtı | AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)jqlang · jq · CWE-121 | Yüksek7,7 | — | %0,5 | 21 May 2025 |
30İzleyin | CVE-2026-32316İstismar yok | jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflowjqlang · jq · CWE-122 | Yüksek7,5 | — | %0,5 | 13 Nis 2026 |
28İzleyin | CVE-2026-49839İstismar yok | jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflowjqlang · jq · CWE-787 | Yüksek7,1 | — | %0,2 | 25 Haz 2026 |
27İzleyin | CVE-2026-39979İstismar yok | jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffersjqlang · jq · CWE-125 | Orta6,9 | — | %0,8 | 13 Nis 2026 |
27İzleyin | CVE-2026-47770İstismar yok | jq: stack overflow in deep structural equalityjqlang · jq · CWE-674 | Orta6,8 | — | %0,2 | 25 Haz 2026 |
27İzleyin | CVE-2026-54679İstismar yok | jq: potential integer overflow in jvp_string_appendjqlang · jq · CWE-190 | Orta6,9 | — | %0,1 | 25 Haz 2026 |
26İzleyin | CVE-2024-23337İstismar yok | jq has signed integer overflow in jv.c:jvp_array_writejqlang · jq · CWE-190 | Orta6,5 | — | %0,4 | 21 May 2025 |
25İzleyin | CVE-2026-41257İstismar yok | jq: Signed-int overflow in `stack_reallocate` (jq VM stack)jqlang · jq · CWE-190 | Orta6,4 | — | %0,1 | 11 May 2026 |
24İzleyin | CVE-2026-39956İstismar yok | jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosurejqlang · jq · CWE-125 | Orta6,1 | — | %0,2 | 13 Nis 2026 |
22İzleyin | CVE-2023-50246İstismar yok | jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.cjqlang · jq · CWE-120 | Orta5,5 | — | %0,5 | 13 Ara 2023 |
22İzleyin | CVE-2023-50268İstismar yok | jq has stack-based buffer overflow in decNaNsjqlang · jq · CWE-120 | Orta5,5 | — | %0,4 | 13 Ara 2023 |
22İzleyin | CVE-2026-33947İstismar yok | jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()jqlang · jq · CWE-674 | Orta5,5 | — | %0,2 | 13 Nis 2026 |
22İzleyin | CVE-2026-41256İstismar yok | jq: Embedded NUL truncates top-level jq programs loaded with -fjqlang · jq · CWE-158 | Orta5,5 | — | %0,2 | 11 May 2026 |
22İzleyin | CVE-2026-43894İstismar yok | jq: Wild stack write via signed-integer overflow in decNumber D2U() macrojqlang · jq · CWE-190 | Orta5,5 | — | %0,2 | 11 May 2026 |
22İzleyin | CVE-2026-43896İstismar yok | jq: Stack Overflow in Recursive Object Mergejqlang · jq · CWE-674 | Orta5,5 | — | %0,2 | 11 May 2026 |
21İzleyin | CVE-2026-40612İstismar yok | jq: Stack overflow via unbounded recursion in jv_containsjqlang · jq · CWE-674 | Orta5,4 | — | %0,2 | 11 May 2026 |
21İzleyin | CVE-2026-44777İstismar yok | jq: stack overflow in module loading on mutual `include`jqlang · jq · CWE-674 | Orta5,4 | — | %0,2 | 11 May 2026 |
17İzleyin | CVE-2026-43895İstismar yok | jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifactsjqlang · jq · CWE-20 | Orta4,4 | — | %0,2 | 11 May 2026 |
11İzleyin | CVE-2026-33948İstismar yok | jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Inputjqlang · jq · CWE-20 | Düşük2,9 | — | %0,3 | 13 Nis 2026 |
7İzleyin | CVE-2025-9403İstismar yok | jqlang jq JSON jq_test.c run_jq_tests assertionjqlang · jq · CWE-617 | Düşük1,9 | — | %0,2 | 24 Ağu 2025 |
- CVE-2024-5342732İzleyin
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-
YüksekCVSS 8,1İstismar yokEPSS %0jqlang · jq26 Şub 2025
- CVE-2023-4935530İzleyin
decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input.
YüksekCVSS 7,5İstismar yokEPSS %1jqlang · jq11 Ara 2023
- CVE-2025-4806030İzleyin
AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
YüksekCVSS 7,7Kavram kanıtıEPSS %1jqlang · jq21 May 2025
- CVE-2026-3231630İzleyin
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
YüksekCVSS 7,5İstismar yokEPSS %0jqlang · jq13 Nis 2026
- CVE-2026-4983928İzleyin
jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
YüksekCVSS 7,1İstismar yokEPSS %0jqlang · jq25 Haz 2026
- CVE-2026-3997927İzleyin
jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
OrtaCVSS 6,9İstismar yokEPSS %1jqlang · jq13 Nis 2026
- CVE-2026-4777027İzleyin
jq: stack overflow in deep structural equality
OrtaCVSS 6,8İstismar yokEPSS %0jqlang · jq25 Haz 2026
- CVE-2026-5467927İzleyin
jq: potential integer overflow in jvp_string_append
OrtaCVSS 6,9İstismar yokEPSS %0jqlang · jq25 Haz 2026
- CVE-2024-2333726İzleyin
jq has signed integer overflow in jv.c:jvp_array_write
OrtaCVSS 6,5İstismar yokEPSS %0jqlang · jq21 May 2025
- CVE-2026-4125725İzleyin
jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
OrtaCVSS 6,4İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-3995624İzleyin
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
OrtaCVSS 6,1İstismar yokEPSS %0jqlang · jq13 Nis 2026
- CVE-2023-5024622İzleyin
jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c
OrtaCVSS 5,5İstismar yokEPSS %1jqlang · jq13 Ara 2023
- CVE-2023-5026822İzleyin
jq has stack-based buffer overflow in decNaNs
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq13 Ara 2023
- CVE-2026-3394722İzleyin
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq13 Nis 2026
- CVE-2026-4125622İzleyin
jq: Embedded NUL truncates top-level jq programs loaded with -f
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4389422İzleyin
jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4389622İzleyin
jq: Stack Overflow in Recursive Object Merge
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4061221İzleyin
jq: Stack overflow via unbounded recursion in jv_contains
OrtaCVSS 5,4İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4477721İzleyin
jq: stack overflow in module loading on mutual `include`
OrtaCVSS 5,4İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4389517İzleyin
jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
OrtaCVSS 4,4İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-3394811İzleyin
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
DüşükCVSS 2,9İstismar yokEPSS %0jqlang · jq13 Nis 2026
- CVE-2025-94037İzleyin
jqlang jq JSON jq_test.c run_jq_tests assertion
DüşükCVSS 1,9İstismar yokEPSS %0jqlang · jq24 Ağu 2025