rpm package
opensuse/json-c&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/json-c&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-11322 | Med | 6.5 | < 0.19-1.1 | 0.19-1.1 | Jun 4, 2026 | Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the designated workspace root. Attackers can exploit the workspace file and listing AP | |
| CVE-2013-6371 | — | < 0.12.1-1.3 | 0.12.1-1.3 | Apr 22, 2014 | The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions. | ||
| CVE-2013-6370 | — | < 0.12.1-1.3 | 0.12.1-1.3 | Apr 22, 2014 | Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors. |
- affected < 0.19-1.1fixed 0.19-1.1
Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the designated workspace root. Attackers can exploit the workspace file and listing AP
- CVE-2013-6371Apr 22, 2014affected < 0.12.1-1.3fixed 0.12.1-1.3
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
- CVE-2013-6370Apr 22, 2014affected < 0.12.1-1.3fixed 0.12.1-1.3
Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.