Lucene search

K
cvelistCertccCVELIST:CVE-2016-4303
HistorySep 26, 2016 - 2:00 p.m.

CVE-2016-4303

2016-09-2614:00:00
certcc
www.cve.org
4

AI Score

9.6

Confidence

High

EPSS

0.017

Percentile

87.9%

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.

AI Score

9.6

Confidence

High

EPSS

0.017

Percentile

87.9%