cbcvebase.

Radareorg Radare2 vulnerabilities

17 known vulnerabilities affecting radareorg/radare2.

Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH11MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-1744P3CRITICALCVSS 9.8fixed in <5.9.92025-02-28
CVE-2025-1744 [CRITICAL] CWE-787 CVE-2025-1744: Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffe Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.
nvd
CVE-2025-1864P3CRITICALCVSS 9.8fixed in <5.9.92025-03-03
CVE-2025-1864 [CRITICAL] CWE-119 CVE-2025-1864: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg r Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.
nvd
CVE-2026-40499P3HIGHCVSS 7.8fixed in 6.1.42026-04-15
CVE-2026-40499 [HIGH] CWE-78 CVE-2026-40499: radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_ radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed wh
nvd
CVE-2026-40527P3HIGHCVSS 7.8fixed in bc5a89033db3ecb5b1f7bf681fc6ba4dcfc146832026-04-17
CVE-2026-40527 [HIGH] CWE-78 CVE-2026-40527: radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequ
nvd
CVE-2026-14789P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-06
CVE-2026-14789 [HIGH] CWE-119 CVE-2026-14789: A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknow A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The pa
nvd
CVE-2020-15121P3CRITICALCVSS 9.6fixed in 4.5.02020-07-20
CVE-2020-15121 [CRITICAL] CWE-78 CVE-2020-15121: In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injecti In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.
nvd
CVE-2026-40517P3HIGHCVSS 7.8fixed in 6.1.42026-04-22
CVE-2026-40517 [HIGH] CWE-78 CVE-2026-40517: radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsanitized symbol name interpolation in the flag rename command
nvd
CVE-2026-14759P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-05
CVE-2026-14759 [HIGH] CWE-119 CVE-2026-14759: A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the functio A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been relea
nvd
CVE-2026-14788P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-06
CVE-2026-14788 [HIGH] CWE-119 CVE-2026-14788: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulner A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c
nvd
CVE-2026-6941P3HIGHCVSS 7.8fixed in 6.1.42026-04-23
CVE-2026-6941 [HIGH] CWE-59 CVE-2026-6941: radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that al radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement ch
nvd
CVE-2026-14757P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-05
CVE-2026-14757 [HIGH] CWE-189 CVE-2026-14757: A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.
nvd
CVE-2026-14787P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-06
CVE-2026-14787 [HIGH] CWE-189 CVE-2026-14787: A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handler. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch n
nvd
CVE-2026-14760P3HIGHCVSS 7.8v6.1.0v6.1.1+5 more2026-07-05
CVE-2026-14760 [HIGH] CWE-119 CVE-2026-14760: A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_see A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This
nvd
CVE-2026-6940P4HIGHCVSS 7.1fixed in 6.1.42026-04-23
CVE-2026-6940 [HIGH] CWE-22 CVE-2026-6940: radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive de
nvd
CVE-2026-14758P4MEDIUMCVSS 5.5v6.1.0v6.1.1+5 more2026-07-05
CVE-2026-14758 [MEDIUM] CWE-189 CVE-2026-14758: A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the func A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. The exploit is publicly available and might be used. The name of the pat
nvd
CVE-2026-14761P4MEDIUMCVSS 5.5v6.1.0v6.1.1+5 more2026-07-05
CVE-2026-14761 [MEDIUM] CWE-189 CVE-2026-14761: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is a20a56917ae8
nvd
CVE-2026-14786P4MEDIUMCVSS 5.5v6.1.0v6.1.1+5 more2026-07-06
CVE-2026-14786 [MEDIUM] CWE-189 CVE-2026-14786: A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_st A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0
nvd
Radareorg Radare2 vulnerabilities | cvebase