VDB
CVE-2022-1452
CVE-2022-1452
PUBLISHED
CVSS 7.099999904632568 HIGH
Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).
EPSS 0.80% · 53.9th percentile
Risk Scores
CVSS 3.0
7.099999904632568
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
0.80%
53.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| radare | radare2 | 0 |
| radareorg | radareorg/radare2 | unspecified |
Timeline
- Apr 24, 2022 CVE Published
- Apr 25, 2022 EPSS Score
- Jun 14, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Sep 23, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Feb 20, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 7, 2023 EPSS Score