VYPR

Ghidra

by Nationalsecurityagency

Source repositories

CVEs (24)

  • CVE-2026-52757MedJun 10, 2026
    risk 0.22cvss 4.4epss 0.00

    Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap…

  • CVE-2026-49497LowJun 10, 2026
    risk 0.21cvss 3.3epss 0.00

    Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem…

  • CVE-2024-58350LowJun 10, 2026
    risk 0.19cvss 2.9epss 0.00

    Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during…

  • CVE-2023-22671CriJan 6, 2023
    risk 0.00cvss 9.8epss 0.03

    Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.

Page 2 of 2