Radare Radare2 vulnerabilities
169 known vulnerabilities affecting radare/radare2.
Total CVEs
169
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH71MEDIUM72LOW10
Vulnerabilities
Page 7 of 9
CVE-2018-10186P4MEDIUMCVSS 5.5v2.5.02018-04-17
CVE-2018-10186 [MEDIUM] CVE-2018-10186: In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/he
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.
nvd
CVE-2018-20457P4MEDIUMCVSS 5.5≤ 3.1.32018-12-25
CVE-2018-20457 [MEDIUM] CWE-125 CVE-2018-20457: In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to c
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-
nvd
CVE-2018-12322P4MEDIUMCVSS 5.5v2.6.02018-06-13
CVE-2018-12322 [MEDIUM] CWE-125 CVE-2018-12322: There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a c
There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.
nvd
CVE-2021-44974P4MEDIUMCVSS 5.5fixed in 5.5.42022-05-25
CVE-2021-44974 [MEDIUM] CWE-476 CVE-2021-44974: radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols
radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.
nvd
CVE-2022-1382P4MEDIUMCVSS 5.5fixed in 5.6.82022-04-18
CVE-2022-1382 [MEDIUM] CWE-476 CVE-2022-1382: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability i
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.
nvd
CVE-2022-0849P4MEDIUMCVSS 5.5fixed in 5.6.62022-03-05
CVE-2022-0849 [MEDIUM] CWE-416 CVE-2022-0849: Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
nvd
CVE-2025-60360P4MEDIUMCVSS 5.5≤ 5.9.82025-10-17
CVE-2025-60360 [MEDIUM] CWE-401 CVE-2025-60360: radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
nvd
CVE-2025-60359P4MEDIUMCVSS 5.5≤ 5.9.82025-10-17
CVE-2025-60359 [MEDIUM] CWE-401 CVE-2025-60359: radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
nvd
CVE-2018-11377P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11377 [MEDIUM] CWE-125 CVE-2018-11377: The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service
The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2017-6415P4MEDIUMCVSS 5.5v1.2.12017-03-02
CVE-2017-6415 [MEDIUM] CWE-476 CVE-2017-6415: The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers t
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.
nvd
CVE-2018-11379P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11379 [MEDIUM] CWE-125 CVE-2018-11379: The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service
The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
nvd
CVE-2018-11375P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11375 [MEDIUM] CWE-125 CVE-2018-11375: The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (hea
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2018-11383P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11383 [MEDIUM] CWE-908 CVE-2018-11383: The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.
nvd
CVE-2018-11382P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11382 [MEDIUM] CWE-125 CVE-2018-11382: The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (hea
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2018-11376P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11376 [MEDIUM] CWE-125 CVE-2018-11376: The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (he
The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
nvd
CVE-2018-11384P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11384 [MEDIUM] CWE-125 CVE-2018-11384: The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-bas
The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
nvd
CVE-2017-7854P4MEDIUMCVSS 5.5v1.3.02017-04-13
CVE-2017-7854 [MEDIUM] CWE-125 CVE-2017-7854: The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial
The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
nvd
CVE-2017-6387P4MEDIUMCVSS 5.5v1.2.12017-03-02
CVE-2017-6387 [MEDIUM] CWE-125 CVE-2017-6387: The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
nvd
CVE-2018-20456P4MEDIUMCVSS 5.5fixed in 3.1.12018-12-25
CVE-2018-20456 [MEDIUM] CVE-2018-20456: In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attack
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.
nvd
CVE-2018-19843P4MEDIUMCVSS 5.5fixed in 3.1.12018-12-04
CVE-2018-19843 [MEDIUM] CWE-125 CVE-2018-19843: opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of servi
opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
nvd