9.8
CVSSv3

CVE-2019-11835

Published: 09/05/2019 Updated: 03/05/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

cJSON prior to 1.7.11 allows out-of-bounds access, related to multiline comments.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cjson project cjson

oracle timesten in-memory database

Vendor Advisories

Debian Bug report logs - #928726 json: CVE-2019-11834 CVE-2019-11835 Package: src:cjson; Maintainer for src:cjson is Yanhao Mo <yanhaocs@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 9 May 2019 18:03:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in version cjso ...