« List of all CVEs

CVE-2022-1452

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in radareorg/radare2

Published: 4/24/2022 Last updated: 8/3/2024 Reserved: 4/24/2022

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CNA assigner: @huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.1 High CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Opam packages affected (2)

conf-radare2 radare2

Products affected (1)

Product Vendor Version
radareorg/radare2 radareorg < 2025.3

References (4)