cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDavegamble Cjson
APPDavegamble< 1.7.11Oracle Timesten In Memory Database
APPOracle< 18.1.3.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
References
Related vulnerabilities
CVE-2026-60402CRITICAL9.9PL ✓same product
Krytyczne przejęcie kontroli nad Oracle TimesTen In-Memory Database przez Kubernetes Operator
CVE-2025-57052CRITICAL9.8PL ✓same product
Out-of-bounds access w cJSON przez funkcję decode_array_index_from_pointer
CVE-2019-11834CRITICAL9.8PL ✓same product
cJSON: out-of-bounds access przez znak \x00 w literale tekstowym
CVE-2016-10749CRITICAL9.8PL ✓same product
Buffer over-read w funkcji parse_string biblioteki cJSON
CVE-2018-11058CRITICAL9.8PL ✓same product
Buffer Over-Read w RSA BSAFE podczas parsowania danych ASN.1