Total vulnerabilities in the database
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Software | From | Fixed in |
---|---|---|
iperf3_project / iperf3 | 3.1 | 3.1.3 |
iperf3_project / iperf3 | 3.0 | 3.0.12 |
novell / suse_package_hub_for_suse_linux_enterprise | 12 | 12.x |
opensuse / leap | 42.1 | 42.1.x |
opensuse / opensuse | 13.2 | 13.2.x |
debian / debian_linux | 8.0 | 8.0.x |