Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53154

Опубликовано: 23 мая 2025
Источник: nvd
CVSS3: 2.9
CVSS3: 5.5
EPSS Низкий

Описание

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cjson_project:cjson:*:*:*:*:*:*:*:*
Версия до 1.7.18 (исключая)

EPSS

Процентиль: 16%
0.00242
Низкий

2.9 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 2.9
ubuntu
около 1 года назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 5.1
redhat
около 1 года назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
msrc
5 дней назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
debian
около 1 года назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read ...

CVSS3: 2.9
github
около 1 года назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

EPSS

Процентиль: 16%
0.00242
Низкий

2.9 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-125