Radare Radare2 vulnerabilities

153 known vulnerabilities affecting radare/radare2.

Total CVEs
153
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH60MEDIUM70LOW9

Vulnerabilities

Page 6 of 8
CVE-2018-20460MEDIUMCVSS 5.5fixed in 3.1.22018-12-25
CVE-2018-20460 [MEDIUM] CWE-787 CVE-2018-20460: In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attacke In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
nvd
CVE-2018-20457MEDIUMCVSS 5.5≤ 3.1.32018-12-25
CVE-2018-20457 [MEDIUM] CWE-125 CVE-2018-20457: In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to c In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-
nvd
CVE-2018-20459MEDIUMCVSS 5.5≤ 3.1.32018-12-25
CVE-2018-20459 [MEDIUM] CVE-2018-20459: In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attacker In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
nvd
CVE-2018-20461MEDIUMCVSS 5.5fixed in 3.1.12018-12-25
CVE-2018-20461 [MEDIUM] CWE-125 CVE-2018-20461: In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denia In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
nvd
CVE-2018-20455MEDIUMCVSS 5.5fixed in 3.1.12018-12-25
CVE-2018-20455 [MEDIUM] CWE-787 CVE-2018-20455: In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attack In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.
nvd
CVE-2018-19843MEDIUMCVSS 5.5fixed in 3.1.12018-12-04
CVE-2018-19843 [MEDIUM] CWE-125 CVE-2018-19843: opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of servi opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
nvd
CVE-2018-19842MEDIUMCVSS 5.5fixed in 3.1.02018-12-04
CVE-2018-19842 [MEDIUM] CWE-125 CVE-2018-19842: getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of se getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
nvd
CVE-2018-15834MEDIUMCVSS 5.5fixed in 2.9.02018-09-12
CVE-2018-15834 [MEDIUM] CWE-787 CVE-2018-15834: In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_function In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.
nvd
CVE-2018-14016MEDIUMCVSS 5.5v2.7.02018-07-12
CVE-2018-14016 [MEDIUM] CWE-125 CVE-2018-14016: The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to c The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.
nvd
CVE-2018-14015MEDIUMCVSS 5.5≥ 2.0.0, ≤ 2.7.02018-07-12
CVE-2018-14015 [MEDIUM] CWE-119 CVE-2018-14015: The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.
nvd
CVE-2018-14017MEDIUMCVSS 5.5v2.7.02018-07-12
CVE-2018-14017 [MEDIUM] CWE-125 CVE-2018-14017: The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted .class file because of missing input validation in r_bin_java_line_number_table_attr_new.
nvd
CVE-2018-12320HIGHCVSS 7.8v2.6.02018-06-13
CVE-2018-12320 [HIGH] CWE-416 CVE-2018-12320: There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
nvd
CVE-2018-12321HIGHCVSS 7.8v2.6.02018-06-13
CVE-2018-12321 [HIGH] CWE-125 CVE-2018-12321: There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c v There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.
nvd
CVE-2018-12322MEDIUMCVSS 5.5v2.6.02018-06-13
CVE-2018-12322 [MEDIUM] CWE-125 CVE-2018-12322: There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a c There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.
nvd
CVE-2018-11378HIGHCVSS 7.8v2.5.02018-05-22
CVE-2018-11378 [HIGH] CWE-119 CVE-2018-11378: The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact vi The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
nvd
CVE-2018-11380MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11380 [MEDIUM] CWE-125 CVE-2018-11380: The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of servic The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
nvd
CVE-2018-11379MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11379 [MEDIUM] CWE-125 CVE-2018-11379: The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
nvd
CVE-2018-11376MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11376 [MEDIUM] CWE-125 CVE-2018-11376: The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (he The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
nvd
CVE-2018-11377MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11377 [MEDIUM] CWE-125 CVE-2018-11377: The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2018-11375MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11375 [MEDIUM] CWE-125 CVE-2018-11375: The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (hea The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd