Loading HuntDB...

Version unspecified

OTHER 44 CVEs

Known Vulnerabilities

CVE-2023-5686

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

MEDIUM CVSS 5.1 Published Oct 20, 2023

CVE-2023-4322

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

HIGH CVSS 7.3 Published Aug 14, 2023

CVE-2023-1605

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

HIGH CVSS 7.5 Published Mar 23, 2023

CVE-2023-0302

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.

HIGH CVSS 8.6 Published Jan 15, 2023

CVE-2022-4843

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.

MEDIUM CVSS 4.4 Published Dec 29, 2022

CVE-2022-4398

Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.

MEDIUM CVSS 6.1 Published Dec 10, 2022

CVE-2022-1899

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

HIGH CVSS 7.7 Published May 26, 2022

CVE-2022-1809

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

HIGH CVSS 7.4 Published May 21, 2022

CVE-2022-1714

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

HIGH CVSS 7.9 Published May 13, 2022

CVE-2022-1649

Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).

HIGH CVSS 7.6 Published May 10, 2022

CVE-2022-1451

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

HIGH CVSS 7.1 Published Apr 24, 2022

CVE-2022-1452

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

HIGH CVSS 7.1 Published Apr 24, 2022

CVE-2022-1444

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

HIGH CVSS 7.5 Published Apr 23, 2022

CVE-2022-1437

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

MEDIUM CVSS 5.3 Published Apr 22, 2022

CVE-2022-1383

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

MEDIUM CVSS 4.8 Published Apr 17, 2022

CVE-2022-1382

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

MEDIUM CVSS 5.3 Published Apr 16, 2022

CVE-2022-1297

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

MEDIUM CVSS 6.6 Published Apr 11, 2022

CVE-2022-1296

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

MEDIUM CVSS 6.6 Published Apr 11, 2022

CVE-2022-1284

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

HIGH CVSS 7.5 Published Apr 08, 2022

CVE-2022-1283

NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).

MEDIUM CVSS 6.6 Published Apr 08, 2022

CVE-2022-1240

Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

HIGH CVSS 7.6 Published Apr 06, 2022

CVE-2022-1237

Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

HIGH CVSS 7.6 Published Apr 06, 2022

CVE-2022-1238

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

HIGH CVSS 7.6 Published Apr 06, 2022

CVE-2022-1244

heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

HIGH CVSS 7.5 Published Apr 05, 2022

CVE-2022-1207

Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.

MEDIUM CVSS 6.6 Published Apr 01, 2022

CVE-2022-1052

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

HIGH CVSS 7.3 Published Mar 24, 2022

CVE-2022-1061

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

HIGH CVSS 7.3 Published Mar 24, 2022

CVE-2022-1031

Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

HIGH CVSS 7.3 Published Mar 22, 2022

CVE-2022-0849

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

HIGH CVSS 7.3 Published Mar 05, 2022

CVE-2022-0695

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

MEDIUM CVSS 6.8 Published Feb 24, 2022

CVE-2022-0476

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

HIGH CVSS 7.3 Published Feb 23, 2022

CVE-2022-0713

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

MEDIUM CVSS 5.3 Published Feb 22, 2022

CVE-2022-0712

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

MEDIUM CVSS 5.9 Published Feb 22, 2022

CVE-2022-0676

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

HIGH CVSS 7.8 Published Feb 22, 2022

CVE-2022-0559

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

HIGH CVSS 8.4 Published Feb 16, 2022

CVE-2022-0522

Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

MEDIUM CVSS 6.3 Published Feb 08, 2022

CVE-2022-0521

Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

MEDIUM CVSS 6.3 Published Feb 08, 2022

CVE-2022-0520

Use After Free in NPM radare2.js prior to 5.6.2.

HIGH CVSS 8.8 Published Feb 08, 2022

CVE-2022-0519

Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

MEDIUM CVSS 6.3 Published Feb 08, 2022

CVE-2022-0518

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

MEDIUM CVSS 6.3 Published Feb 08, 2022

CVE-2022-0139

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

HIGH CVSS 7.1 Published Feb 08, 2022

CVE-2022-0523

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

HIGH CVSS 8.8 Published Feb 08, 2022

CVE-2022-0419

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

MEDIUM CVSS 5.9 Published Feb 01, 2022

CVE-2022-0173

radare2 is vulnerable to Out-of-bounds Read

CRITICAL CVSS 9.6 Published Jan 11, 2022