Json C is a widely embedded JSON parsing library with a minimal product footprint that sits deep in software supply chains across systems, servers, and applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Json C over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32292CRITICAL An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which i | Aug 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-12762HIGH json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. | May 9, 2020 | 7.8 | 21 | NO | NO |
CVE-2013-6371MEDIUM The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions. | Apr 22, 2014 | 5.0 | 17 | NO | NO |
CVE-2013-6370MEDIUM Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors. | Apr 22, 2014 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Json C.
Media articles that mention a CVE ID that affects a product developed by Json C — matched by CVE ID, not by vendor name.