Picoc is a small, interpreted C-like programming language implementation that maintains a modest but persistent vulnerability footprint among embedded scripting and educational use cases. The exposure concentrates in the core interpreter product and recurs through memory-safety weaknesses including out-of-bounds writes and NULL-pointer dereferences, characteristic of dynamically interpreted language runtimes. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Picoc Project over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16277HIGH PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. | Sep 13, 2019 | 7.8 | 24 | NO | NO |
CVE-2022-44312MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator. | Nov 8, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-44321MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from LexScanGetToken. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44319MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44317MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44316MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when called from LexScanGetToken. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44315MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c when called from ExpressionParseFunctionCall. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44314MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExpressionParseFunctionCall. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-44313MEDIUM PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall. | Nov 8, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-34556MEDIUM PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c. | Jul 28, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Picoc Project.
Media articles that mention a CVE ID that affects a product developed by Picoc Project — matched by CVE ID, not by vendor name.