VendorsRadareradare2all versions
Vulnerabilities

Radare 2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

170CVEs
CVE-2017-15932
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
Published 2017-10-27 · Modified
7.8EPSS 0.012
CVE-2022-0676
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-02-22 · Modified
7.8EPSS 0.012
CVE-2017-15385
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.
Published 2017-10-16 · Modified
7.8EPSS 0.011
CVE-2018-11378
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
Published 2018-05-22 · Modified
7.8EPSS 0.011
CVE-2017-16357
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
Published 2017-11-01 · Modified
7.8EPSS 0.010
CVE-2018-12320
There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
Published 2018-06-13 · Modified
7.8EPSS 0.010
CVE-2018-12321
There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.
Published 2018-06-13 · Modified
7.8EPSS 0.010
CVE-2022-1031
Use After Free in op_is_set_bp in radareorg/radare2
Published 2022-03-22 · Modified
7.8EPSS 0.010
CVE-2017-16358
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
Published 2017-11-01 · Modified
7.8EPSS 0.010
CVE-2022-1809
Access of Uninitialized Pointer in radareorg/radare2
Published 2022-05-21 · Modified
7.8EPSS 0.009
CVE-2022-1238
Out-of-bounds Write in libr/bin/format/ne/ne.c in radareorg/radare2
Published 2022-04-06 · Modified
7.8EPSS 0.008
CVE-2022-1237
Improper Validation of Array Index in radareorg/radare2
Published 2022-04-06 · Modified
7.8EPSS 0.008
CVE-2022-1240
Heap buffer overflow in libr/bin/format/mach0/mach0.c in radareorg/radare2
Published 2022-04-06 · Modified
7.8EPSS 0.007
CVE-2022-4398
Integer Overflow or Wraparound in radareorg/radare2
Published 2022-12-10 · Modified
7.8EPSS 0.003
CVE-2024-29645
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.
Published 2024-12-02 · Analyzed
7.8EPSS 0.002
CVE-2026-14759
radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow
Published 2026-07-05 · Analyzed
7.8EPSS 0.002
CVE-2026-14789
radareorg radare2 Memory64ListStream mdmp.c stack-based overflow
Published 2026-07-06 · Analyzed
7.8EPSS 0.002
CVE-2026-6941
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
Published 2026-04-23 · Analyzed
7.8EPSS 0.002
CVE-2026-14757
radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow
Published 2026-07-05 · Analyzed
7.8EPSS 0.002
CVE-2026-14787
radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
Published 2026-07-06 · Analyzed
7.8EPSS 0.002
CVE-2026-14760
radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free
Published 2026-07-05 · Analyzed
7.8EPSS 0.002
CVE-2026-14788
radareorg radare2 cfile.c r_core_bin_load use after free
Published 2026-07-06 · Analyzed
7.8EPSS 0.002
CVE-2022-1649
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2
Published 2022-05-10 · Modified
7.6EPSS 0.007
CVE-2017-9763
The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.
Published 2017-06-19 · Modified
7.5EPSS 0.042
CVE-2020-17487
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
Published 2020-08-11 · Modified
7.5EPSS 0.018
CVE-2021-3673
A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
Published 2021-08-02 · Modified
7.5EPSS 0.018
CVE-2019-12829
radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm/asm.c and libr/parse/parse.c.
Published 2019-06-15 · Modified
7.5EPSS 0.018
CVE-2020-27795
A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing segmentation fault later in ensure_fcn_range (fcn).
Published 2022-08-19 · Modified
7.5EPSS 0.015
CVE-2023-47016
radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.
Published 2023-11-22 · Modified
7.5EPSS 0.012
CVE-2020-27793
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.
Published 2022-08-19 · Modified
7.5EPSS 0.011
CVE-2021-4021
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.
Published 2022-02-24 · Modified
7.5EPSS 0.010
CVE-2023-1605
Denial of Service in radareorg/radare2
Published 2023-03-23 · Modified
7.5EPSS 0.010
CVE-2022-1061
Heap Buffer Overflow in parseDragons in radareorg/radare2
Published 2022-03-24 · Modified
7.5EPSS 0.010
CVE-2022-28071
A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-28070
A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-28073
A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-28068
A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-28072
A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-28069
A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0.
Published 2023-08-22 · Modified
7.5EPSS 0.009
CVE-2022-1244
heap-buffer-overflow in radareorg/radare2
Published 2022-04-05 · Modified
7.5EPSS 0.008
← Prev2 / 5Next →