cbcvebase.

Debian Radare2 vulnerabilities

146 known vulnerabilities affecting debian/radare2.

Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40

Vulnerabilities

Page 2 of 8
CVE-2022-28073P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28073 [HIGH] CVE-2022-28073: radare2 - A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0. A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2022-28072P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28072 [HIGH] CVE-2022-28072: radare2 - A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2022-28068P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28068 [HIGH] CVE-2022-28068: radare2 - A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2023-46569P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-46569 [CRITICAL] CVE-2023-46569: radare2 - An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_f... An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2023-46570P3CRITICALCVSS 9.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-46570 [CRITICAL] CVE-2023-46570: radare2 - An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 f... An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1899P3CRITICALCVSS 9.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1899 [CRITICAL] CVE-2022-1899: radare2 - Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-9763P3LOWCVSS 7.5fixed in grub2 2.02~beta2-8 (bookworm)2017
CVE-2017-9763 [HIGH] CVE-2017-9763: grub2 - The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as... The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array. Scope: local bookworm: resolved (fixed in 2.02~beta2-8) bullseye: resolved
debian
CVE-2020-17487P3HIGHCVSS 7.5fixed in radare2 5.0.0+dfsg-1 (sid)2020
CVE-2020-17487 [HIGH] CVE-2020-17487: radare2 - radare2 4.5.0 misparses signature information in PE files, causing a segmentatio... radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY. Scope: local sid: resolved (fixed in 5.0.0+dfsg-1)
debian
CVE-2022-1238P3HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1238 [HIGH] CVE-2022-1238: radare2 - Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/ra... Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html). Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1237P3HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1237 [HIGH] CVE-2022-1237: radare2 - Improper Validation of Array Index in GitHub repository radareorg/radare2 prior ... Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html). Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2020-27795P3HIGHCVSS 7.5fixed in radare2 5.0.0+dfsg-1 (sid)2020
CVE-2020-27795 [HIGH] CVE-2020-27795: radare2 - A segmentation fault was discovered in radare2 with adf command. In libr/core/cm... A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing segmentation fault later in ensure_fcn_range (fcn). Scope: local sid: resolved (fixed in
debian
CVE-2023-47016P3HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-47016 [HIGH] CVE-2023-47016: radare2 - radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bo... radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2024-29645P3HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2024
CVE-2024-29645 [HIGH] CVE-2024-29645: radare2 - Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to ... Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-28069P3HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28069 [HIGH] CVE-2022-28069: radare2 - A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2022-1240P3HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1240 [HIGH] CVE-2022-1240: radare2 - Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radar... Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/
debian
CVE-2017-10929P4LOWCVSS 7.8fixed in radare2 1.6.0+dfsg-1 (sid)2017
CVE-2017-10929 [HIGH] CVE-2017-10929: radare2 - The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remot... The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02. Scope: local sid
debian
CVE-2022-0676P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0676 [HIGH] CVE-2022-0676: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4... Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2019-12829P4HIGHCVSS 7.5fixed in radare2 3.8.0+dfsg-1 (sid)2019
CVE-2019-12829 [HIGH] CVE-2019-12829: radare2 - radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers t... radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm/asm.c and libr/parse/parse.c. Scope: local sid: resolved (fixed in 3.8.0+dfsg-1)
debian
CVE-2021-32494P4CRITICALCVSS 10.0fixed in radare2 5.5.0+dfsg-1 (sid)2021
CVE-2021-32494 [CRITICAL] CVE-2021-32494: radare2 - Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer fu... Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2022-28070P4HIGHCVSS 7.5fixed in radare2 5.5.0+dfsg-1 (sid)2022
CVE-2022-28070 [HIGH] CVE-2022-28070: radare2 - A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. Scope: local sid: resolved (fixed in 5.5.0+dfsg-1)
debian
Debian Radare2 vulnerabilities | cvebase