CVE-2019-16277: Picoc Project Picoc

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.

Affected products

Published 2019-09-13. Last modified 2026-06-17.