Debian Radare2 vulnerabilities
146 known vulnerabilities affecting debian/radare2.
Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40
Vulnerabilities
Page 3 of 8
CVE-2017-6194P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-4 (sid)2017
CVE-2017-6194 [HIGH] CVE-2017-6194: radare2 - The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote atta...
The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.
Scope: local
sid: resolved (fixed in 1.1.0+dfsg-4)
debian
CVE-2017-6448P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-4 (sid)2017
CVE-2017-6448 [HIGH] CVE-2017-6448: radare2 - The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allo...
The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Scope: local
sid: resolved (fixed in 1.1.0+dfsg-4)
debian
CVE-2019-12790P4HIGHCVSS 7.8fixed in radare2 3.8.0+dfsg-1 (sid)2019
CVE-2019-12790 [HIGH] CVE-2019-12790: radare2 - In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_la...
In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c.
Scope: local
sid: resolved (fixed in 3.8.0+dfsg-1)
debian
CVE-2019-19647P4HIGHCVSS 7.8fixed in radare2 4.2.1+dfsg-1 (sid)2019
CVE-2019-19647 [HIGH] CVE-2019-19647: radare2 - radare2 through 4.0.0 lacks validation of the content variable in the function r...
radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.
Scope: local
sid: resolved (fixed in 4.2.1+dfsg-1)
debian
CVE-2022-0523P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0523 [HIGH] CVE-2022-0523: radare2 - Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-16357P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16357 [HIGH] CVE-2017-16357: radare2 - In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_g...
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-12320P4LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12320 [HIGH] CVE-2018-12320: radare2 - There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c...
There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
Scope: local
sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2022-1031P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1031 [HIGH] CVE-2022-1031: radare2 - Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5...
Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1809P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1809 [HIGH] CVE-2022-1809: radare2 - Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to ...
Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2023-1605P4HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-1605 [HIGH] CVE-2023-1605: radare2 - Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1061P4HIGHCVSS 7.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1061 [HIGH] CVE-2022-1061: radare2 - Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prio...
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-9949P4HIGHCVSS 7.8fixed in radare2 1.6.0+dfsg-1 (sid)2017
CVE-2017-9949 [HIGH] CVE-2017-9949: radare2 - The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remot...
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02.
Scope: local
sid: resolved (fixed in 1.6.0+dfsg-1)
debian
CVE-2017-15932P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15932 [HIGH] CVE-2017-15932: radare2 - In radare2 2.0.1, an integer exception (negative number leading to an invalid me...
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2017-15931P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15931 [HIGH] CVE-2017-15931: radare2 - In radare2 2.0.1, an integer exception (negative number leading to an invalid me...
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-12321P4LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12321 [HIGH] CVE-2018-12321: radare2 - There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/...
There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.
Scope: local
sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2017-16358P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16358 [HIGH] CVE-2017-16358: radare2 - In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range...
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2023-0302P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2023
CVE-2023-0302 [HIGH] CVE-2023-0302: radare2 - Failure to Sanitize Special Elements into a Different Plane (Special Element Inj...
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-4398P4HIGHCVSS 7.8fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-4398 [HIGH] CVE-2022-4398: radare2 - Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5...
Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2019-12802P4HIGHCVSS 7.8fixed in radare2 3.8.0+dfsg-1 (sid)2019
CVE-2019-12802 [HIGH] CVE-2019-12802: radare2 - In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishan...
In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid free in rcc_pusharg).
Scope: local
sid: resolved (fixed in 3.8.0+dfsg-1)
debian
CVE-2017-6319P4HIGHCVSS 7.8fixed in radare2 1.1.0+dfsg-3 (sid)2017
CVE-2017-6319 [HIGH] CVE-2017-6319: radare2 - The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allow...
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Scope: local
sid: resolved (fixed in 1.1.0+dfsg-3)
debian