Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
radare radare2 vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2017-15368
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote malicious users to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_b...
Radare Radare2 2.0.0
5.5
CVSSv3
CVE-2017-16805
In radare2 2.0.1, libr/bin/dwarf.c allows remote malicious users to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.
Radare Radare2 2.0.1
5.5
CVSSv3
CVE-2017-9761
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote malicious users to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Radare Radare2 1.5.0
5.5
CVSSv3
CVE-2017-9762
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote malicious users to cause a denial of service (use-after-free and application crash) via a crafted binary file.
Radare Radare2 1.5.0
7.5
CVSSv3
CVE-2017-9763
The grub_ext2_read_block function in fs/ext2.c in GNU GRUB prior to 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote malicious users to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a v...
Radare Radare2 1.5.0
5.5
CVSSv3
CVE-2018-10186
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.
Radare Radare2 2.5.0
5.5
CVSSv3
CVE-2018-10187
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was ...
Radare Radare2 2.5.0
5.5
CVSSv3
CVE-2018-14016
The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote malicious users to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.
Radare Radare2 2.7.0
7.8
CVSSv3
CVE-2017-16357
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
Radare Radare2 2.0.1
5.5
CVSSv3
CVE-2017-16359
In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.
Radare Radare2 2.0.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »