rpm package
opensuse/radare2&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/radare2&distro=openSUSE%20Tumbleweed
Vulnerabilities (51)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-0522 | Hig | 7.1 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2. | |
| CVE-2022-0521 | Hig | 7.1 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| CVE-2022-0520 | Hig | 7.8 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Use After Free in NPM radare2.js prior to 5.6.2. | |
| CVE-2022-0519 | Hig | 7.1 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| CVE-2022-0518 | Hig | 7.1 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| CVE-2022-0139 | Cri | 9.8 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. | |
| CVE-2022-0419 | Med | 5.5 | < 5.7.0-1.1 | 5.7.0-1.1 | Feb 1, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. | |
| CVE-2022-0173 | Med | 5.5 | < 5.7.0-1.1 | 5.7.0-1.1 | Jan 11, 2022 | radare2 is vulnerable to Out-of-bounds Read | |
| CVE-2021-3673 | Hig | 7.5 | < 5.3.1-2.2 | 5.3.1-2.2 | Aug 2, 2021 | A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. | |
| CVE-2021-32613 | Med | 5.5 | < 5.3.1-2.2 | 5.3.1-2.2 | May 14, 2021 | In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. | |
| CVE-2017-10929 | Hig | 7.8 | < 5.3.1-2.2 | 5.3.1-2.2 | Jul 5, 2017 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in |
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Use After Free in NPM radare2.js prior to 5.6.2.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
- affected < 5.7.0-1.1fixed 5.7.0-1.1
radare2 is vulnerable to Out-of-bounds Read
- affected < 5.3.1-2.2fixed 5.3.1-2.2
A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
- affected < 5.3.1-2.2fixed 5.3.1-2.2
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
- affected < 5.3.1-2.2fixed 5.3.1-2.2
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in
Page 3 of 3