Description
Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
Published: 2026-03-24
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

RetroDebugger implements a debugger that handles user‑supplied input for memory inspection. An out‑of‑bounds read allows the debugger to read memory locations outside the intended buffer, potentially exposing internal data or configuration information to the caller. This vulnerability belongs to CWE-125, which describes an access beyond the bounds of allocated memory and can lead to unintended disclosure of confidential information.

Affected Systems

The flaw affects all releases of RetroDebugger before version 0.64.72. Users running any earlier version of the tool, regardless of the operating system, are at risk if the debugger is accessed by an adversary capable of crafting malicious inspection requests.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity rating, reflecting the potential for significant data exposure. No EPSS score is available, and the vulnerability is not yet listed in the CISA KEV catalog. Because the attack requires interacting with the debugger interface, the most likely vectors are local or remote access to the machine where the debugger is running, but the description does not explicitly state the required privilege level. The risk assessment therefore relies on the high severity score and the nature of the flaw rather than on documented exploitation evidence.

Generated by OpenCVE AI on March 24, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RetroDebugger to version 0.64.72 or later to remove the out‑of‑bounds read issue.

Generated by OpenCVE AI on March 24, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Mar 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Slajerek
Slajerek retrodebugger
Vendors & Products Slajerek
Slajerek retrodebugger

Tue, 24 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
Title Out-of-bounds Read in slajerek RetroDebugger
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Slajerek Retrodebugger
cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published:

Updated: 2026-03-24T14:27:54.384Z

Reserved: 2026-03-24T05:40:49.837Z

Link: CVE-2026-4753

cve-icon Vulnrichment

Updated: 2026-03-24T14:27:51.204Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-24T06:16:23.700

Modified: 2026-03-24T15:53:48.067

Link: CVE-2026-4753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T20:40:01Z

Weaknesses