python-cjson
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting python-cjsonpage 1 of 1
- CVE-2009-4924MEDIUMCVSS v2 4.3EG 4.3fixed in 1.1.02010-07-02
vulnerable: 1.0.0 ... 1.0.5 (6 versions)
Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.
- CVE-2010-1666MEDIUMCVSS v2 6.8EG 6.8fixed in 1.0.5.1 or 1.1.0, by version range2010-07-02
vulnerable: 1.0.0 ... 1.0.5 (6 versions)
Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Un…
Check whether python-cjson is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for python-cjson CVEs against the assets you own.
Book a Demo →