Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53154

Опубликовано: 23 мая 2025
Источник: nvd
CVSS3: 2.9
CVSS3: 5.5
EPSS Низкий

Описание

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cjson_project:cjson:*:*:*:*:*:*:*:*
Версия до 1.7.18 (исключая)

EPSS

Процентиль: 4%
0.00018
Низкий

2.9 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 2.9
ubuntu
8 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 5.1
redhat
8 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
msrc
5 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
debian
8 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read ...

CVSS3: 2.9
github
8 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

EPSS

Процентиль: 4%
0.00018
Низкий

2.9 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-125