CVE-2015-4590

ArduinoJson < 4.4 - Denial of Service via Malformed JSON String

Title source: llm
STIX 2.1

Description

The extractFrom function in Internals/QuotedString.cpp in Arduino JSON before 4.5 allows remote attackers to cause a denial of service (crash) via a JSON string with a \ (backslash) followed by a terminator, as demonstrated by "\\\0", which triggers a buffer overflow and over-read.

Scores

EPSS 0.0265
EPSS Percentile 83.7%

Details

CWE
CWE-119
Status published
Products (1)
arduino_json_project/arduino_json < 4.4
Published Jun 22, 2015
Tracked Since Feb 18, 2026