CVE-2016-10749

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
29/04/2019
Last modified:
22/07/2025

Description

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* 0.0.0 (excluding)