cbcvebase.

Debian Radare2 vulnerabilities

146 known vulnerabilities affecting debian/radare2.

Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40

Vulnerabilities

Page 3 of 8
CVE-2017-6194P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-4 (sid)2017
CVE-2017-6194 [HIGH] CVE-2017-6194: radare2 - The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote atta... The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file. Scope: local sid: resolved (fixed in 1.1.0+dfsg-4)
debian
CVE-2017-6448P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-4 (sid)2017
CVE-2017-6448 [HIGH] CVE-2017-6448: radare2 - The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allo... The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file. Scope: local sid: resolved (fixed in 1.1.0+dfsg-4)
debian
CVE-2019-12790P4HIGHCVSS 7.8fixed in radare2 3.8.0+dfsg-1 (sid)2019
CVE-2019-12790 [HIGH] CVE-2019-12790: radare2 - In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_la... In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c. Scope: local sid: resolved (fixed in 3.8.0+dfsg-1)
debian
CVE-2019-19647P4HIGHCVSS 7.8fixed in radare2 4.2.1+dfsg-1 (sid)2019
CVE-2019-19647 [HIGH] CVE-2019-19647: radare2 - radare2 through 4.0.0 lacks validation of the content variable in the function r... radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input. Scope: local sid: resolved (fixed in 4.2.1+dfsg-1)
debian
CVE-2022-0523P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0523 [HIGH] CVE-2022-0523: radare2 - Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-16357P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16357 [HIGH] CVE-2017-16357: radare2 - In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_g... In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory. Scope: local sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-12320P4LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12320 [HIGH] CVE-2018-12320: radare2 - There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c... There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file. Scope: local sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2022-1031P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1031 [HIGH] CVE-2022-1031: radare2 - Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5... Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1809P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1809 [HIGH] CVE-2022-1809: radare2 - Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to ... Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2023-1605P4HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-1605 [HIGH] CVE-2023-1605: radare2 - Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1061P4HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1061 [HIGH] CVE-2022-1061: radare2 - Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prio... Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-9949P4HIGHCVSS 7.8fixed in radare2 1.6.0+dfsg-1 (sid)2017
CVE-2017-9949 [HIGH] CVE-2017-9949: radare2 - The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remot... The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02. Scope: local sid: resolved (fixed in 1.6.0+dfsg-1)
debian
CVE-2017-15932P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15932 [HIGH] CVE-2017-15932: radare2 - In radare2 2.0.1, an integer exception (negative number leading to an invalid me... In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems. Scope: local sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2017-15931P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15931 [HIGH] CVE-2017-15931: radare2 - In radare2 2.0.1, an integer exception (negative number leading to an invalid me... In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems. Scope: local sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-12321P4LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12321 [HIGH] CVE-2018-12321: radare2 - There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/... There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file. Scope: local sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2017-16358P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16358 [HIGH] CVE-2017-16358: radare2 - In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range... In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search. Scope: local sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2023-0302P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-0302 [HIGH] CVE-2023-0302: radare2 - Failure to Sanitize Special Elements into a Different Plane (Special Element Inj... Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-4398P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-4398 [HIGH] CVE-2022-4398: radare2 - Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5... Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0. Scope: local sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2019-12802P4HIGHCVSS 7.8fixed in radare2 3.8.0+dfsg-1 (sid)2019
CVE-2019-12802 [HIGH] CVE-2019-12802: radare2 - In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishan... In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid free in rcc_pusharg). Scope: local sid: resolved (fixed in 3.8.0+dfsg-1)
debian
CVE-2017-6319P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-3 (sid)2017
CVE-2017-6319 [HIGH] CVE-2017-6319: radare2 - The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allow... The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file. Scope: local sid: resolved (fixed in 1.1.0+dfsg-3)
debian
Debian Radare2 vulnerabilities | cvebase