296,733
Total vulnerabilities in the database
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| iperf3_project / iperf3 | 3.1 | 3.1.3 |
| iperf3_project / iperf3 | 3.0 | 3.0.12 |
| novell / suse_package_hub_for_suse_linux_enterprise | 12 | 12.x |
| opensuse / leap | 42.1 | 42.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| debian / debian_linux | 8.0 | 8.0.x |