CVE-2022-29368 is an out-of-bounds read vulnerability affecting Moddable products prior to commit 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45, specifically within the fxUint8Getter function in xsDataView.c. Rated as HIGH severity (CVSS 7.1), this vulnerability can be triggered locally with low complexity, requiring user interaction, and could lead to high confidentiality impact and high availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= os220330CPE matchmatch criteria | cpe:2.3:a:moddable:moddable:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.