Debian Radare2 vulnerabilities
146 known vulnerabilities affecting debian/radare2.
Total CVEs
146
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM41LOW40
Vulnerabilities
Page 4 of 8
CVE-2018-11378P4LOWCVSS 7.8fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11378 [HIGH] CVE-2018-11378: radare2 - The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspeci...
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
Scope: local
sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2017-15368P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15368 [HIGH] CVE-2017-15368: radare2 - The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remot...
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2017-15385P4HIGHCVSS 7.8fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-15385 [HIGH] CVE-2017-15385: radare2 - The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare...
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2022-1714P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1714 [HIGH] CVE-2022-1714: radare2 - Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bu...
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-0518P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0518 [HIGH] CVE-2022-0518: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2...
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-0713P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0713 [HIGH] CVE-2022-0713: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4...
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-0519P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0519 [HIGH] CVE-2022-0519: radare2 - Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2...
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1451P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1451 [HIGH] CVE-2022-1451: radare2 - Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repo...
Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mit
debian
CVE-2022-1452P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1452 [HIGH] CVE-2022-1452: radare2 - Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub r...
Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.
debian
CVE-2022-0521P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-0521 [HIGH] CVE-2022-0521: radare2 - Access of Memory Location After End of Buffer in GitHub repository radareorg/rad...
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1437P4HIGHCVSS 7.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1437 [HIGH] CVE-2022-1437: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0...
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1207P4MEDIUMCVSS 6.6fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1207 [MEDIUM] CVE-2022-1207: radare2 - Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This v...
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1383P4MEDIUMCVSS 6.1fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1383 [MEDIUM] CVE-2022-1383: radare2 - Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8...
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2021-32613P4MEDIUMCVSS 5.5fixed in radare2 5.5.0+dfsg-1 (sid)2021
CVE-2021-32613 [MEDIUM] CVE-2021-32613: radare2 - In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse v...
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
Scope: local
sid: resolved (fixed in 5.5.0+dfsg-1)
debian
CVE-2021-44975P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2021
CVE-2021-44975 [MEDIUM] CVE-2021-44975: radare2 - radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_obj...
radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2022-1649P4MEDIUMCVSS 5.5fixed in radare2 5.9.0+dfsg-1 (sid)2022
CVE-2022-1649 [MEDIUM] CVE-2022-1649: radare2 - Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 i...
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
debian
CVE-2017-16359P4MEDIUMCVSS 5.5fixed in radare2 2.1.0+dfsg-1 (sid)2017
CVE-2017-16359 [MEDIUM] CVE-2017-16359: radare2 - In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_...
In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.
Scope: local
sid: resolved (fixed in 2.1.0+dfsg-1)
debian
CVE-2018-20460P4LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20460 [MEDIUM] CVE-2018-20460: radare2 - In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armas...
In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
Scope: local
sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-20455P4LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20455 [MEDIUM] CVE-2018-20455: radare2 - In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_n...
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.
Scope: local
sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-10187P4LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-10187 [MEDIUM] CVE-2018-10187: radare2 - In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op functi...
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier.
Scope: local
sid: resolved (fixed in 2.6.0+dfsg-1)
debian