CVE-2022-1297
published 2022-04-11CVE-2022-1297: Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read…
PriorityP338critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.86%
54.5th percentile
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.0+dfsg-1 (sid) | radare2 5.9.0+dfsg-1 (sid) |
| radare | radare2 | < 5.6.8 | 5.6.8 |
| radareorg | radareorg_radare2 | >= unspecified < 5.6.8 | 5.6.8 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv3.06.6MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
cisa8.8HIGH
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Memory Corruption Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2010-1297 [HIGH] CWE-787 Adobe Flash Player Memory Corruption Vulnerability
Vulnerability: Adobe Flash Player Memory Corruption Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-1297
Remediation Due Date: 2022-06-22
CISA
Microsoft Excel Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2019-1297 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Vulnerability: Microsoft Excel Remote Code Execution Vulnerability
Affected: Microsoft Excel
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1297
Remediation Due Date: 2022-03-17
Debian
CVE-2022-1297: radare2 - Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository rad...
vendor_debian·2022·CVSS 9.1
CVE-2022-1297 [CRITICAL] CVE-2022-1297: radare2 - Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository rad...
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
GHSA
GHSA-25cp-hxpp-ffqx: Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5
ghsa_unreviewed·2022-04-12
CVE-2022-1297 [CRITICAL] CWE-125 GHSA-25cp-hxpp-ffqx: Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
OSV
CVE-2022-1297: Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5
osv·2022-04-11·CVSS 9.1
CVE-2022-1297 [CRITICAL] CVE-2022-1297: Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-11
Published