Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
radare2 vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2022-1383
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 before 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow malicious users to read sensitive information from other memory locations or cause a crash.
Radare Radare2
NA
CVE-2023-0302
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 before 5.8.2.
Radare Radare2
NA
CVE-2020-27793
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an malicious user to cause a crash, and perform a denail of service attack.
Radare Radare2
NA
CVE-2020-27794
A double free issue exists in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
Radare Radare2
NA
CVE-2020-27795
A segmentation fault exists in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fc...
Radare Radare2
605
VMScore
CVE-2019-12790
In radare2 up to and including 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length...
Radare Radare2
445
VMScore
CVE-2019-12829
radare2 up to and including 3.5.1 mishandles the RParse API, which allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm...
Radare Radare2
605
VMScore
CVE-2017-16357
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
Radare Radare2 2.0.1
605
VMScore
CVE-2017-16358
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
Radare Radare2 2.0.1
383
VMScore
CVE-2018-8809
In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
Radare Radare2 2.4.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »