Loading HuntDB...

Vulnerabilities

CVE-2023-5686

MEDIUM

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

Published Oct 20, 2023

CVE-2023-4322

HIGH

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

Published Aug 14, 2023

CVE-2023-1605

HIGH

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

Published Mar 23, 2023

CVE-2023-0302

HIGH

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.

Published Jan 15, 2023

CVE-2022-4843

MEDIUM

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.

Published Dec 29, 2022

CVE-2022-4398

MEDIUM

Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.

Published Dec 10, 2022

CVE-2022-1899

HIGH

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

Published May 26, 2022

CVE-2022-1809

HIGH

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

Published May 21, 2022

CVE-2022-1714

HIGH

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

Published May 13, 2022

CVE-2022-1649

HIGH

Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).

Published May 10, 2022

CVE-2022-1451

HIGH

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

Published Apr 24, 2022

CVE-2022-1452

HIGH

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

Published Apr 24, 2022

CVE-2022-1444

HIGH

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

Published Apr 23, 2022

CVE-2022-1437

MEDIUM

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

Published Apr 22, 2022

CVE-2022-1383

MEDIUM

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

Published Apr 17, 2022

CVE-2022-1382

MEDIUM

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

Published Apr 16, 2022

CVE-2022-1297

MEDIUM

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

Published Apr 11, 2022

CVE-2022-1296

MEDIUM

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

Published Apr 11, 2022

CVE-2022-1284

HIGH

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

Published Apr 08, 2022

CVE-2022-1283

MEDIUM

NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).

Published Apr 08, 2022

CVE-2022-1240

HIGH

Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

Published Apr 06, 2022

CVE-2022-1237

HIGH

Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

Published Apr 06, 2022

CVE-2022-1238

HIGH

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

Published Apr 06, 2022

CVE-2022-1244

HIGH

heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

Published Apr 05, 2022

CVE-2022-1207

MEDIUM

Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.

Published Apr 01, 2022

CVE-2022-1052

HIGH

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

Published Mar 24, 2022

CVE-2022-1061

HIGH

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

Published Mar 24, 2022

CVE-2022-1031

HIGH

Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

Published Mar 22, 2022

CVE-2022-0849

HIGH

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

Published Mar 05, 2022

CVE-2022-0695

MEDIUM

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

Published Feb 24, 2022

CVE-2022-0476

HIGH

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

Published Feb 23, 2022

CVE-2022-0713

MEDIUM

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

Published Feb 22, 2022

CVE-2022-0712

MEDIUM

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

Published Feb 22, 2022

CVE-2022-0676

HIGH

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

Published Feb 22, 2022

CVE-2022-0559

HIGH

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

Published Feb 16, 2022

CVE-2022-0522

MEDIUM

Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0521

MEDIUM

Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0520

HIGH

Use After Free in NPM radare2.js prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0519

MEDIUM

Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0518

MEDIUM

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0139

HIGH

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

Published Feb 08, 2022

CVE-2022-0523

HIGH

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

Published Feb 08, 2022

CVE-2022-0419

MEDIUM

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

Published Feb 01, 2022

CVE-2022-0173

CRITICAL

radare2 is vulnerable to Out-of-bounds Read

Published Jan 11, 2022

CVE-2020-15121

HIGH

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.

Published Jul 20, 2020