← back
CVE-2022-0522mediumCWE-786

Access of Memory Location Before Start of Buffer in radareorg/radare2

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3epss 1.0%
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
In short

A memory access vulnerability in the radare2.js library allows an attacker to read data from memory locations before the intended buffer, potentially exposing sensitive information. This flaw affects versions before 5.6.2.

Technical detail

CWE-786 out-of-bounds read vulnerability in radare2.js NPM package prior to version 5.6.2; allows reading memory before allocated buffer boundaries through improper bounds checking, potentially disclosing sensitive data; requires interaction with malformed input to trigger the vulnerability.

Summary generated and translated by AI from the official description.
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L