CVE detail
CVE-2020-8244 — CVE-2020-8244
Published 2020-08-30 · Modified 2026-06-17 · Vendor bufferlist_project · Product bufferlist · Source nvd
MEDIUM
severity
CVSS-derived band
0.0218
EPSS probability
exploitation probability, 30d
81.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References