← Back

Radare2

radare2

Vendor: Radare • 170 CVEs

CVEs (170)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Radare
1Radare2
Nov 21, 2024
May 22, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
1Radare
1Radare2
Nov 21, 2024
Apr 17, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note...Show more
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier.Show less
1Radare
1Radare2
Nov 21, 2024
Apr 17, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue...Show more
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.Show less
1Radare
1Radare2
Jun 17, 2026
Mar 20, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file.
1Radare
1Radare2
Jun 17, 2026
Mar 20, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
1Radare
1Radare2
Jun 17, 2026
Mar 20, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
1Radare
1Radare2
May 13, 2026
Nov 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal...Show more
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.Show less
1Radare
1Radare2
May 13, 2026
Nov 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.
1Radare
1Radare2
May 13, 2026
Nov 1, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
1Radare
1Radare2
May 13, 2026
Nov 1, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to impro...Show more
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.Show less
1Radare
1Radare2
May 13, 2026
Oct 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32b...Show more
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.Show less
1Radare
1Radare2
May 13, 2026
Oct 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.
1Radare
1Radare2
May 13, 2026
Oct 16, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified...Show more
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.Show less
1Radare
1Radare2
May 13, 2026
Oct 16, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via...Show more
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call.Show less
1Radare
1Radare2
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a...Show more
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02.Show less
1Radare
1Radare2
May 13, 2026
Jun 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via...Show more
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02.Show less
1Radare
1Radare2
May 13, 2026
Jun 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application cra...Show more
The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.Show less
1Radare
1Radare2
May 13, 2026
Jun 19, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
1Radare
1Radare2
May 13, 2026
Jun 19, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
1Radare
1Radare2
May 13, 2026
Jun 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.