Radare
Products
5- 182 CVEs
- 8 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
183| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32495 | Cri | 0.65 | 10.0 | 0.01 | Jul 7, 2023 | Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service. | ||
| CVE-2021-32494 | Cri | 0.65 | 10.0 | 0.01 | Jul 7, 2023 | Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service. | ||
| CVE-2023-46570 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2023 | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. | ||
| CVE-2023-46569 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2023 | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h. | ||
| CVE-2020-24133 | Cri | 0.64 | 9.8 | 0.03 | Jul 14, 2021 | A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks. | ||
| CVE-2020-27794 | Cri | 0.59 | 9.1 | 0.01 | Aug 19, 2022 | A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash. | ||
| CVE-2026-6942 | Cri | 0.57 | 9.8 | 0.03 | Apr 23, 2026 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject… | ||
| CVE-2024-11858 | Hig | 0.56 | 8.6 | 0.01 | Dec 15, 2024 | A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file… | ||
| CVE-2019-19647 | Hig | 0.51 | 7.8 | 0.02 | Dec 9, 2019 | radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact… | ||
| CVE-2019-19590 | Hig | 0.51 | 7.8 | 0.03 | Dec 5, 2019 | In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free.… | ||
| CVE-2019-14745 | Hig | 0.51 | 7.8 | 0.04 | Aug 7, 2019 | In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of… | ||
| CVE-2019-12802 | Hig | 0.51 | 7.8 | 0.02 | Jun 13, 2019 | In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid… | ||
| CVE-2019-12790 | Hig | 0.51 | 7.8 | 0.02 | Jun 10, 2019 | In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in… | ||
| CVE-2018-12321 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2018 | There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file. | ||
| CVE-2018-12320 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2018 | There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file. | ||
| CVE-2018-11378 | Hig | 0.51 | 7.8 | 0.01 | May 22, 2018 | The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file. | ||
| CVE-2017-16358 | Hig | 0.51 | 7.8 | 0.01 | Nov 1, 2017 | In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search. | ||
| CVE-2017-16357 | Hig | 0.51 | 7.8 | 0.01 | Nov 1, 2017 | In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory. | ||
| CVE-2017-15932 | Hig | 0.51 | 7.8 | 0.01 | Oct 27, 2017 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems. | ||
| CVE-2017-15931 | Hig | 0.51 | 7.8 | 0.01 | Oct 27, 2017 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems. |
- risk 0.65cvss 10.0epss 0.01
Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
- risk 0.65cvss 10.0epss 0.01
Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.
- risk 0.64cvss 9.8epss 0.03
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
- risk 0.59cvss 9.1epss 0.01
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
- risk 0.57cvss 9.8epss 0.03
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject…
- risk 0.56cvss 8.6epss 0.01
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file…
- risk 0.51cvss 7.8epss 0.02
radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact…
- risk 0.51cvss 7.8epss 0.03
In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free.…
- risk 0.51cvss 7.8epss 0.04
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of…
- risk 0.51cvss 7.8epss 0.02
In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid…
- risk 0.51cvss 7.8epss 0.02
In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in…
- risk 0.51cvss 7.8epss 0.01
There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.
- risk 0.51cvss 7.8epss 0.01
There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
- risk 0.51cvss 7.8epss 0.01
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
- risk 0.51cvss 7.8epss 0.01
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
- risk 0.51cvss 7.8epss 0.01
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
- risk 0.51cvss 7.8epss 0.01
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
- risk 0.51cvss 7.8epss 0.01
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.