Back to Database
Status published
Unknown
CVE-2022-36938
DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can...
Vulnerability Description
DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36938
Credits & Attribution
No credits recorded in the NVD database.
More from Facebook
View All →CVE-2025-64296
WordPress Facebook for WooCommerce plugin <= 3.5.7 - Broken Access Control to Notice Dismissal vulnerability
Medium
5.3
CVE-2025-55181
Sending an HTTP request/response body with greater than 2^31 bytes...
Medium
5.3
CVE-2025-55179
Incomplete validation of rich response messages in WhatsApp for iOS...
Medium
5.4
CVE-2025-55177
Incomplete authorization of linked device synchronization messages in WhatsApp for...
Medium
5.4
CVE-2025-30403
A heap-buffer-overflow vulnerability is possible in mvfst via a specially...
Unknown
0
Affected Vendor
Affected Software
Redex
Vulnerable Versions:
unspecified
Timeline
Official Publish:
November 10th, 2022
Last Modified:
May 1st, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available