parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
History

Tue, 22 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Davegamble
Davegamble cjson
CPEs cpe:2.3:a:cjson_project:cjson:*:*:*:*:*:*:*:* cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*
Vendors & Products Cjson Project
Cjson Project cjson
Davegamble
Davegamble cjson

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-29T13:46:59

Updated: 2024-08-06T03:30:20.194Z

Reserved: 2019-04-29T00:00:00

Link: CVE-2016-10749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-29T14:29:00.363

Modified: 2025-07-22T18:17:45.530

Link: CVE-2016-10749

cve-icon Redhat

No data.