cbcvebase.

Debian Radare2 vulnerabilities

146 known vulnerabilities affecting debian/radare2.

Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40

Vulnerabilities

Page 1 of 8
CVE-2025-1744P3CRITICALCVSS 10.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-1744 [CRITICAL] CVE-2025-1744: radare2 - Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffe... Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9. Scope: local sid: resolved (fixed in 6.0.4+dfsg-1)
debian
CVE-2025-1864P3CRITICALCVSS 10.0fixed in radare2 6.0.4+dfsg-1 (sid)2025
CVE-2025-1864 [CRITICAL] CVE-2025-1864: radare2 - Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerab... Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9. Scope: local sid: resolved (fixed in 6.0.4+dfsg-1)
debian
CVE-2024-29646P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2024
CVE-2024-29646 [CRITICAL] CVE-2024-29646: radare2 - Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to ... Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2020-15121P3HIGHCVSS 7.4fixed in radare2 5.0.0+dfsg-1 (sid)2020
CVE-2020-15121 [HIGH] CVE-2020-15121: radare2 - In radare2 before version 4.5.0, malformed PDB file names in the PDB server path... In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory. Scope: local sid: resolved (fixed in 5.0.0+dfsg-1)
debian
CVE-2015-2305P3LOWCVSS 6.8fixed in clamav 0.98.7+dfsg-1 (bookworm)2015
CVE-2015-2305 [MEDIUM] CVE-2015-2305: alpine - Integer overflow in the regcomp implementation in the Henry Spencer BSD regex li... Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow. Scope: local bookworm: resolved bullseye:
debian
CVE-2019-14745P3HIGHCVSS 7.8fixed in radare2 3.9.0+dfsg-1 (sid)2019
CVE-2019-14745 [HIGH] CVE-2019-14745: radare2 - In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols... In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables. Scope: local sid: resolved (fixed in 3.9.0+dfsg-1)
debian
CVE-2022-0559P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0559 [CRITICAL] CVE-2022-0559: radare2 - Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-0139P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0139 [CRITICAL] CVE-2022-0139: radare2 - Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2023-5686P3HIGHCVSS 8.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-5686 [HIGH] CVE-2023-5686: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0... Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2024-11858P3HIGHCVSS 8.6fixed in radare2 5.9.8+dfsg-1 (sid)2024
CVE-2024-11858 [HIGH] CVE-2024-11858: radare2 - A flaw was found in Radare2, which contains a command injection vulnerability ca... A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​ Scope: local sid: resolved (fixed in 5.9.8+dfsg-1)
debian
CVE-2021-32495P3CRITICALCVSS 10.0fixed in radare2 5.5.0+dfsg-1 (sid)2021
CVE-2021-32495 [CRITICAL] CVE-2021-32495: radare2 - Radare2 has a use-after-free vulnerability in pyc parser's get_none_object funct... Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2023-4322P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-4322 [CRITICAL] CVE-2023-4322: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0... Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2021-3673P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2021
CVE-2021-3673 [HIGH] CVE-2021-3673: radare2 - A vulnerability was found in Radare2 in version 5.3.1. Improper input validation... A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2021-4021P3HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2021
CVE-2021-4021 [HIGH] CVE-2021-4021: radare2 - A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 an... A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2020-27794P3CRITICALCVSS 9.1fixed in radare2 5.0.0+dfsg-1 (sid)2020
CVE-2020-27794 [CRITICAL] CVE-2020-27794: radare2 - A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successf... A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash. Scope: local sid: resolved (fixed in 5.0.0+dfsg-1)
debian
CVE-2022-1297P3CRITICALCVSS 9.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1297 [CRITICAL] CVE-2022-1297: radare2 - Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository rad... Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1296P3CRITICALCVSS 9.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1296 [CRITICAL] CVE-2022-1296: radare2 - Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radare... Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2019-19590P3HIGHCVSS 7.8fixed in radare2 4.2.1+dfsg-1 (sid)2019
CVE-2019-19590 [HIGH] CVE-2019-19590: radare2 - In radare2 through 4.0, there is an integer overflow for the variable new_token_... In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote attackers to cause a denial of service (application crash) or possibly
debian
CVE-2020-27793P3HIGHCVSS 7.5fixed in radare2 5.0.0+dfsg-1 (sid)2020
CVE-2020-27793 [HIGH] CVE-2020-27793: radare2 - An off-by-one overflow flaw was found in radare2 due to mismatched array length ... An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack. Scope: local sid: resolved (fixed in 5.0.0+dfsg-1)
debian
CVE-2022-28071P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28071 [HIGH] CVE-2022-28071: radare2 - A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
Debian Radare2 vulnerabilities | cvebase