← back
CVE-2020-8244CWE-126

CVE-2020-8244

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.2%
exploitation probability
2.2%top 18% of all CVEs
observed exploitation
nono source reports it
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Affected products
n/a · bl