VYPR
Vendor

Radare

Products
5
CVEs
174
Across products
183
Status
Private

Products

5

Recent CVEs

174
View all 174 CVEs →
  • CVE-2023-46570CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46569CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2026-6942CriApr 23, 2026
    risk 0.57cvss 9.8epss 0.02

    radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject…

  • CVE-2024-11858HigDec 15, 2024
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file…

  • CVE-2019-19647HigDec 9, 2019
    risk 0.51cvss 7.8epss 0.02

    radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact…

  • CVE-2019-19590HigDec 5, 2019
    risk 0.51cvss 7.8epss 0.03

    In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free.…

  • CVE-2019-12802HigJun 13, 2019
    risk 0.51cvss 7.8epss 0.02

    In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid…

  • CVE-2019-12790HigJun 10, 2019
    risk 0.51cvss 7.8epss 0.02

    In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in…

  • CVE-2017-16358HigNov 1, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.

  • CVE-2017-16357HigNov 1, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.

  • CVE-2017-15932HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.

  • CVE-2017-15931HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.

  • CVE-2017-15385HigOct 16, 2017
    risk 0.51cvss 7.8epss 0.01

    The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.

  • CVE-2017-15368HigOct 16, 2017
    risk 0.51cvss 7.8epss 0.01

    The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect…

  • CVE-2017-10929HigJul 5, 2017
    risk 0.51cvss 7.8epss 0.02

    The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in…

  • CVE-2017-9949HigJun 26, 2017
    risk 0.51cvss 7.8epss 0.02

    The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer…

  • CVE-2017-6448HigApr 3, 2017
    risk 0.51cvss 7.8epss 0.02

    The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.

  • CVE-2017-6194HigApr 3, 2017
    risk 0.51cvss 7.8epss 0.02

    The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.

  • CVE-2017-6319HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.

  • CVE-2021-4021HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.