VDB

CVE-2022-38216

CVE-2022-38216 PUBLISHED CVSS 7.5 HIGH

An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

EPSS 0.83% · 56.1th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.83%
56.1th percentile

Affected Products

VendorProductVersions
Mavencom.mapbox.mapboxsdk:mapbox-android-core0
mapboxmaps_software_development_kit0
MapboxMapboxunspecified

Timeline

  • Aug 16, 2022 EPSS Score
  • Aug 16, 2022 CVE Published
  • Oct 1, 2022 EPSS Score
  • Nov 17, 2022 EPSS Score
  • Nov 22, 2022 CVE Updated
  • Jan 2, 2023 EPSS Score
  • Feb 18, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 5, 2023 EPSS Score
  • May 21, 2023 EPSS Score
  • Jul 7, 2023 EPSS Score
  • Aug 22, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›