Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
radare2 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2018-20460
In radare2 before 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows malicious users to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
Radare Radare2
445
VMScore
CVE-2022-1061
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 before 5.6.8.
Radare Radare2
383
VMScore
CVE-2022-1649
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 before 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
Radare Radare2
605
VMScore
CVE-2022-1809
Access of Uninitialized Pointer in GitHub repository radareorg/radare2 before 5.7.0.
Radare Radare2
570
VMScore
CVE-2022-1899
Out-of-bounds Read in GitHub repository radareorg/radare2 before 5.7.0.
Radare Radare2
383
VMScore
CVE-2022-1244
heap-buffer-overflow in GitHub repository radareorg/radare2 before 5.6.8. This vulnerability is capable of inducing denial of service.
Radare Radare2
383
VMScore
CVE-2022-1284
heap-use-after-free in GitHub repository radareorg/radare2 before 5.6.8. This vulnerability is capable of inducing denial of service.
Radare Radare2
570
VMScore
CVE-2022-1297
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 before 5.6.8. This vulnerability may allow malicious users to read sensitive information or cause a crash.
Radare Radare2
NA
CVE-2023-47016
radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.
Radare Radare2
605
VMScore
CVE-2022-1240
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 before 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For...
Radare Radare2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »