Radare Radare2 vulnerabilities
153 known vulnerabilities affecting radare/radare2.
Total CVEs
153
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH60MEDIUM70LOW9
Vulnerabilities
Page 8 of 8
CVE-2017-9761MEDIUMCVSS 5.5v1.5.02017-06-19
CVE-2017-9761 [MEDIUM] CWE-119 CVE-2017-9761: The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
nvd
CVE-2017-9762MEDIUMCVSS 5.5v1.5.02017-06-19
CVE-2017-9762 [MEDIUM] CWE-416 CVE-2017-9762: The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a de
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
nvd
CVE-2017-9520MEDIUMCVSS 5.5v1.5.02017-06-08
CVE-2017-9520 [MEDIUM] CWE-416 CVE-2017-9520: The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
nvd
CVE-2017-7946MEDIUMCVSS 5.5v1.3.02017-04-18
CVE-2017-7946 [MEDIUM] CWE-416 CVE-2017-7946: The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
nvd
CVE-2017-7854MEDIUMCVSS 5.5v1.3.02017-04-13
CVE-2017-7854 [MEDIUM] CWE-125 CVE-2017-7854: The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial
The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
nvd
CVE-2017-7716MEDIUMCVSS 5.5v1.3.02017-04-12
CVE-2017-7716 [MEDIUM] CWE-125 CVE-2017-7716: The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to caus
The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
nvd
CVE-2017-6194HIGHCVSS 7.8v1.2.12017-04-03
CVE-2017-6194 [HIGH] CWE-119 CVE-2017-6194: The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a den
The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.
nvdosv
CVE-2017-6448HIGHCVSS 7.8v1.2.12017-04-03
CVE-2017-6448 [HIGH] CWE-119 CVE-2017-6448: The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers
The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
nvd
CVE-2017-7274MEDIUMCVSS 5.5v1.3.02017-03-27
CVE-2017-7274 [MEDIUM] CWE-476 CVE-2017-7274: The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to ca
The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.
nvdosv
CVE-2017-6319HIGHCVSS 7.8v1.2.12017-03-02
CVE-2017-6319 [HIGH] CWE-119 CVE-2017-6319: The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers t
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
nvdosv
CVE-2017-6387MEDIUMCVSS 5.5v1.2.12017-03-02
CVE-2017-6387 [MEDIUM] CWE-125 CVE-2017-6387: The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
nvd
CVE-2017-6415MEDIUMCVSS 5.5v1.2.12017-03-02
CVE-2017-6415 [MEDIUM] CWE-476 CVE-2017-6415: The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers t
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.
nvd
CVE-2017-6197MEDIUMCVSS 5.5v1.2.12017-02-24
CVE-2017-6197 [MEDIUM] CWE-476 CVE-2017-6197: The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a
The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.
nvd
← Previous8 / 8