VYPR

Python Cjson

by Dan Pascu

CVEs (2)

  • CVE-2009-4924Jul 2, 2010
    risk 0.00cvss epss 0.00

    Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

  • CVE-2010-1666Jul 2, 2010
    risk 0.00cvss epss 0.01

    Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Unicode input to the cjson.encode function.