Back to Database
Status published
Medium
CVE-2022-0522
Access of Memory Location Before Start of Buffer in radareorg/radare2
Vulnerability Description
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0522
Credits & Attribution
No credits recorded in the NVD database.
References
- https://huntr.dev/bounties/2d45e589-d614-4875-bba1-be0f729e7ca9
- https://github.com/radareorg/radare2/commit/d17a7bdf166108a29a27cd89bf454f9fa6c050d6
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E6YBRQ3UCFWJVSOYIKPVUDASZ544TFND/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZTIMAS53YT66FUS4QHQAFRJOBMUFG6D/
More from radareorg
View All →CVE-2025-1864
Buffer Overflow and Potential Code Execution in Radare2
Critical
10
CVE-2025-1744
Out-of-bounds Write in radare2
Critical
10
CVE-2023-5686
Heap-based Buffer Overflow in radareorg/radare2
Medium
5.1
CVE-2023-4322
Heap-based Buffer Overflow in radareorg/radare2
High
7.3
CVE-2023-1605
Denial of Service in radareorg/radare2
High
7.5
Affected Vendor
radareorg
View all reports →Affected Software
radareorg/radare2
Vulnerable Versions:
unspecified
Timeline
Official Publish:
February 8th, 2022
Last Modified:
August 2nd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.