VYPR

Vendor CVEs

Radare

All CVEs

165 total · sorted by risk
  • CVE-2026-6942CriApr 23, 2026
    risk 0.57cvss 9.8epss 0.02

    radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject…

  • CVE-2017-16358HigNov 1, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.

  • CVE-2017-16357HigNov 1, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.

  • CVE-2017-15932HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.

  • CVE-2017-15931HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.01

    In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.

  • CVE-2017-15385HigOct 16, 2017
    risk 0.51cvss 7.8epss 0.01

    The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.

  • CVE-2017-15368HigOct 16, 2017
    risk 0.51cvss 7.8epss 0.01

    The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect…

  • CVE-2017-10929HigJul 5, 2017
    risk 0.51cvss 7.8epss 0.02

    The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in…

  • CVE-2017-9949HigJun 26, 2017
    risk 0.51cvss 7.8epss 0.02

    The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer…

  • CVE-2017-6448HigApr 3, 2017
    risk 0.51cvss 7.8epss 0.02

    The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.

  • CVE-2017-6194HigApr 3, 2017
    risk 0.51cvss 7.8epss 0.02

    The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.

  • CVE-2017-6319HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.

  • CVE-2017-9763HigJun 19, 2017
    risk 0.49cvss 7.5epss 0.04

    The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a…

  • CVE-2026-40517HigApr 22, 2026
    risk 0.44cvss 7.8epss 0.01

    radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2…

  • CVE-2026-40527HigApr 17, 2026
    risk 0.44cvss 7.8epss 0.01

    radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF…

  • CVE-2026-40499HigApr 15, 2026
    risk 0.44cvss 7.8epss 0.01

    radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with…

  • CVE-2026-8696HigMay 15, 2026
    risk 0.42cvss 7.5epss 0.01

    radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can…

  • CVE-2026-8695HigMay 15, 2026
    risk 0.42cvss 7.5epss 0.01

    radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability…

  • CVE-2026-41015HigApr 16, 2026
    risk 0.41cvss 7.4epss 0.01

    radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after…

  • CVE-2026-6940HigApr 23, 2026
    risk 0.39cvss 7.1epss 0.00

    radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to…

  • CVE-2026-6941MedApr 23, 2026
    risk 0.36cvss 6.6epss 0.00

    radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a…

  • CVE-2018-10187MedApr 17, 2018
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was…

  • CVE-2018-10186MedApr 17, 2018
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.

  • CVE-2018-8810MedMar 20, 2018
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file.

  • CVE-2018-8809MedMar 20, 2018
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.

  • CVE-2018-8808MedMar 20, 2018
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.

  • CVE-2017-16805MedNov 13, 2017
    risk 0.36cvss 5.5epss 0.01

    In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.

  • CVE-2017-16359MedNov 1, 2017
    risk 0.36cvss 5.5epss 0.01

    In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.

  • CVE-2017-9762MedJun 19, 2017
    risk 0.36cvss 5.5epss 0.01

    The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.

  • CVE-2017-9761MedJun 19, 2017
    risk 0.36cvss 5.5epss 0.01

    The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.

  • CVE-2017-9520MedJun 8, 2017
    risk 0.36cvss 5.5epss 0.01

    The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.

  • CVE-2017-7946MedApr 18, 2017
    risk 0.36cvss 5.5epss 0.01

    The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.

  • CVE-2017-7854MedApr 13, 2017
    risk 0.36cvss 5.5epss 0.01

    The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

  • CVE-2017-7716MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.01

    The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

  • CVE-2017-7274MedMar 27, 2017
    risk 0.36cvss 5.5epss 0.02

    The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.

  • CVE-2017-6415MedMar 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.

  • CVE-2017-6387MedMar 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.

  • CVE-2017-6197MedFeb 24, 2017
    risk 0.36cvss 5.5epss 0.02

    The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.

  • CVE-2018-15834MedSep 12, 2018
    risk 0.29cvss 5.5epss 0.01

    In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.

  • CVE-2018-14017MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted .class file because of missing input validation in…

  • CVE-2018-14016MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.

  • CVE-2018-14015MedJul 12, 2018
    risk 0.29cvss 5.5epss 0.01

    The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.

  • CVE-2026-4174LowMar 16, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local…

  • CVE-2025-63744Nov 14, 2025
    risk 0.00cvss epss 0.00

    A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

  • CVE-2025-63745Nov 14, 2025
    risk 0.00cvss epss 0.00

    A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.

  • CVE-2025-60361Oct 17, 2025
    risk 0.00cvss epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

  • CVE-2025-60359Oct 17, 2025
    risk 0.00cvss epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

  • CVE-2025-60360Oct 17, 2025
    risk 0.00cvss epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

  • CVE-2025-60358Oct 16, 2025
    risk 0.00cvss epss 0.00

    radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

  • CVE-2025-5648Jun 5, 2025
    risk 0.00cvss epss 0.00

    A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached…

Page 1 of 4