VYPR

Radare2

by Radare

Source repositories

CVEs (173)

  • CVE-2018-14015MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.

  • CVE-2026-14757MedJul 5, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be…

  • CVE-2026-14789LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack…

  • CVE-2026-14788LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been…

  • CVE-2026-14787LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handler. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit…

  • CVE-2026-14786LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the…

  • CVE-2026-14761LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been…

  • CVE-2026-14760LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit…

  • CVE-2026-14759LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer…

  • CVE-2026-14758LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally.…

  • CVE-2026-4174LowMar 16, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local…

  • CVE-2025-63745MedNov 14, 2025
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.

  • CVE-2025-63744MedNov 14, 2025
    risk 0.00cvss 4.3epss 0.00

    A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

  • CVE-2025-60361LowOct 17, 2025
    risk 0.00cvss 3.3epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

  • CVE-2025-60360MedOct 17, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

  • CVE-2025-60359MedOct 17, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

  • CVE-2025-60358MedOct 16, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

  • CVE-2025-5648LowJun 5, 2025
    risk 0.00cvss 2.5epss 0.00

    A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached…

  • CVE-2025-5647LowJun 5, 2025
    risk 0.00cvss 2.5epss 0.00

    A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context_break_pop in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. The attack needs to be…

  • CVE-2025-5646LowJun 5, 2025
    risk 0.00cvss 2.5epss 0.00

    A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to…

Page 4 of 9