MidnightBSD

Advisories for jsonparser_project

CVE-2020-10675 MEDIUM

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-835,

Products Affected

Vendor Product Version
jsonparser_project jsonparser *
fedoraproject fedora 31
fedoraproject fedora 32
CVE-2020-35381 HIGH

jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
jsonparser_project jsonparser 1.0.0
fedoraproject fedora 33
fedoraproject fedora 32