Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
radare2 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2019-12829
radare2 up to and including 3.5.1 mishandles the RParse API, which allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm...
Radare Radare2
4.3
CVSSv2
CVE-2019-12865
In radare2 up to and including 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
Radare Radare2
5
CVSSv2
CVE-2022-1061
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 before 5.6.8.
Radare Radare2
5.8
CVSSv2
CVE-2022-1383
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 before 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow malicious users to read sensitive information from other memory locations or cause a crash.
Radare Radare2
6.8
CVSSv2
CVE-2019-12790
In radare2 up to and including 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length...
Radare Radare2
NA
CVE-2023-1605
Denial of Service in GitHub repository radareorg/radare2 before 5.8.6.
Radare Radare2
NA
CVE-2020-27795
A segmentation fault exists in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fc...
Radare Radare2
4.3
CVSSv2
CVE-2018-11376
The r_read_le32() function in radare2 2.5.0 allows remote malicious users to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
Radare Radare2 2.5.0
6.8
CVSSv2
CVE-2018-11378
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
Radare Radare2 2.5.0
4.3
CVSSv2
CVE-2018-11379
The get_debug_info() function in radare2 2.5.0 allows remote malicious users to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
Radare Radare2 2.5.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »