Radare Radare2 vulnerabilities
169 known vulnerabilities affecting radare/radare2.
Total CVEs
169
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH71MEDIUM72LOW10
Vulnerabilities
Page 8 of 9
CVE-2022-0712P4MEDIUMCVSS 5.5fixed in 5.6.42022-02-22
CVE-2022-0712 [MEDIUM] CWE-476 CVE-2022-0712: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2022-0419P4MEDIUMCVSS 5.5fixed in 5.6.02022-02-01
CVE-2022-0419 [MEDIUM] CWE-476 CVE-2022-0419: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
nvd
CVE-2017-7716P4MEDIUMCVSS 5.5v1.3.02017-04-12
CVE-2017-7716 [MEDIUM] CWE-125 CVE-2017-7716: The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to caus
The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
nvd
CVE-2023-27114P4MEDIUMCVSS 5.5v5.8.32023-03-10
CVE-2023-27114 [MEDIUM] CWE-476 CVE-2023-27114: radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/w
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
nvd
CVE-2022-34520P4MEDIUMCVSS 5.5v5.7.22022-07-22
CVE-2022-34520 [MEDIUM] CWE-476 CVE-2022-34520: Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_
Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
nvd
CVE-2024-26475P4MEDIUMCVSS 5.5≥ 0.9.7, < 5.8.82024-03-14
CVE-2024-26475 [MEDIUM] CWE-476 CVE-2024-26475: An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker t
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
nvd
CVE-2024-48241P4MEDIUMCVSS 5.5≥ 5.8.0, ≤ 5.9.42024-10-30
CVE-2024-48241 [MEDIUM] CWE-787 CVE-2024-48241: An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via t
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
nvd
CVE-2025-60358P4MEDIUMCVSS 5.5≤ 5.9.82025-10-16
CVE-2025-60358 [MEDIUM] CWE-401 CVE-2025-60358: radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
nvdosv
CVE-2017-9520P4MEDIUMCVSS 5.5v1.5.02017-06-08
CVE-2017-9520 [MEDIUM] CWE-416 CVE-2017-9520: The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
nvd
CVE-2022-0476P4MEDIUMCVSS 5.5fixed in 5.6.42022-02-23
CVE-2022-0476 [MEDIUM] CWE-400 CVE-2022-0476: Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2017-9762P4MEDIUMCVSS 5.5v1.5.02017-06-19
CVE-2017-9762 [MEDIUM] CWE-416 CVE-2017-9762: The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a de
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
nvd
CVE-2022-0695P4MEDIUMCVSS 5.5fixed in 5.6.42022-02-24
CVE-2022-0695 [MEDIUM] CWE-400 CVE-2022-0695: Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2018-11380P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11380 [MEDIUM] CWE-125 CVE-2018-11380: The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of servic
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
nvd
CVE-2018-11381P4MEDIUMCVSS 5.5v2.5.02018-05-22
CVE-2018-11381 [MEDIUM] CWE-125 CVE-2018-11381: The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of servi
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2017-7946P4MEDIUMCVSS 5.5v1.3.02017-04-18
CVE-2017-7946 [MEDIUM] CWE-416 CVE-2017-7946: The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
nvd
CVE-2017-16805P4MEDIUMCVSS 5.5v2.0.12017-11-13
CVE-2017-16805 [MEDIUM] CWE-125 CVE-2017-16805: In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid rea
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.
nvd
CVE-2018-20461P4MEDIUMCVSS 5.5fixed in 3.1.12018-12-25
CVE-2018-20461 [MEDIUM] CWE-125 CVE-2018-20461: In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denia
In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
nvd
CVE-2018-20458P4MEDIUMCVSS 5.5fixed in 3.1.12018-12-25
CVE-2018-20458 [MEDIUM] CWE-125 CVE-2018-20458: In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow at
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.
nvd
CVE-2022-1283P4MEDIUMCVSS 5.5fixed in 5.6.82022-04-08
CVE-2022-1283 [MEDIUM] CWE-476 CVE-2022-1283: NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2
NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).
nvd
CVE-2025-1378P4LOWCVSS 3.3v5.9.9v5.9.9 332862025-02-17
CVE-2025-1378 [LOW] CWE-119 CVE-2025-1378: A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is ab
nvd