VendorsRadareradare2any version
Vulnerabilities

Radare 2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

100CVEs
CVE-2026-14757
radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow
Published 2026-07-05 · Analyzed
7.8EPSS 0.002
CVE-2026-14787
radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
Published 2026-07-06 · Analyzed
7.8EPSS 0.002
CVE-2026-14760
radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free
Published 2026-07-05 · Analyzed
7.8EPSS 0.002
CVE-2026-14788
radareorg radare2 cfile.c r_core_bin_load use after free
Published 2026-07-06 · Analyzed
7.8EPSS 0.002
CVE-2022-1649
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2
Published 2022-05-10 · Modified
7.6EPSS 0.007
CVE-2019-12829
radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm/asm.c and libr/parse/parse.c.
Published 2019-06-15 · Modified
7.5EPSS 0.018
CVE-2020-27795
A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing segmentation fault later in ensure_fcn_range (fcn).
Published 2022-08-19 · Modified
7.5EPSS 0.015
CVE-2023-47016
radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.
Published 2023-11-22 · Modified
7.5EPSS 0.012
CVE-2020-27793
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.
Published 2022-08-19 · Modified
7.5EPSS 0.011
CVE-2021-4021
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.
Published 2022-02-24 · Modified
7.5EPSS 0.010
CVE-2023-1605
Denial of Service in radareorg/radare2
Published 2023-03-23 · Modified
7.5EPSS 0.010
CVE-2022-1061
Heap Buffer Overflow in parseDragons in radareorg/radare2
Published 2022-03-24 · Modified
7.5EPSS 0.010
CVE-2022-1244
heap-buffer-overflow in radareorg/radare2
Published 2022-04-05 · Modified
7.5EPSS 0.008
CVE-2022-1284
heap-use-after-free in radareorg/radare2
Published 2022-04-08 · Modified
7.5EPSS 0.008
CVE-2022-1444
heap-use-after-free in radareorg/radare2
Published 2022-04-23 · Modified
7.5EPSS 0.008
CVE-2022-4843
NULL Pointer Dereference in radareorg/radare2
Published 2022-12-29 · Modified
7.5EPSS 0.007
CVE-2022-0476
Denial of Service in radareorg/radare2
Published 2022-02-23 · Modified
7.3EPSS 0.010
CVE-2022-0849
Use After Free in r_reg_get_name_idx in radareorg/radare2
Published 2022-03-05 · Modified
7.3EPSS 0.007
CVE-2022-1052
Heap Buffer Overflow in iterate_chained_fixups in radareorg/radare2
Published 2022-03-24 · Modified
7.3EPSS 0.004
CVE-2022-0518
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-02-08 · Modified
7.1EPSS 0.010
CVE-2022-0713
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-02-22 · Modified
7.1EPSS 0.010
CVE-2022-0522
Access of Memory Location Before Start of Buffer in radareorg/radare2
Published 2022-02-08 · Modified
7.1EPSS 0.010
CVE-2022-0521
Access of Memory Location After End of Buffer in radareorg/radare2
Published 2022-02-08 · Modified
7.1EPSS 0.010
CVE-2022-0519
Buffer Access with Incorrect Length Value in radareorg/radare2
Published 2022-02-08 · Modified
7.1EPSS 0.010
CVE-2022-0712
NULL Pointer Dereference in radareorg/radare2
Published 2022-02-22 · Modified
7.1EPSS 0.010
CVE-2022-1451
Out-of-bounds Read in r_bin_java_constant_value_attr_new function in radareorg/radare2
Published 2022-04-24 · Modified
7.1EPSS 0.008
CVE-2022-1452
Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in radareorg/radare2
Published 2022-04-24 · Modified
7.1EPSS 0.008
CVE-2022-1437
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-04-22 · Modified
7.1EPSS 0.008
CVE-2022-1382
NULL Pointer Dereference in radareorg/radare2
Published 2022-04-16 · Modified
7.1EPSS 0.007
CVE-2026-6940
radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion
Published 2026-04-23 · Analyzed
7.1EPSS 0.002
CVE-2022-0695
Denial of Service in radareorg/radare2
Published 2022-02-24 · Modified
6.8EPSS 0.010
CVE-2022-1207
Out-of-bounds read in radareorg/radare2
Published 2022-04-01 · Modified
6.6EPSS 0.009
CVE-2022-1283
NULL Pointer Dereference in r_bin_ne_get_entrypoints function in radareorg/radare2
Published 2022-04-08 · Modified
6.6EPSS 0.007
CVE-2022-1383
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-04-17 · Modified
6.1EPSS 0.008
CVE-2022-0419
NULL Pointer Dereference in radareorg/radare2
Published 2022-02-01 · Modified
5.9EPSS 0.009
CVE-2018-14015
The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.
Published 2018-07-12 · Analyzed
5.5EPSS 0.012
CVE-2021-32613
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
Published 2021-05-14 · Modified
5.5EPSS 0.012
CVE-2018-20460
In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
Published 2018-12-25 · Modified
5.5EPSS 0.011
CVE-2018-20455
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.
Published 2018-12-25 · Modified
5.5EPSS 0.011
CVE-2018-20461
In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
Published 2018-12-25 · Modified
5.5EPSS 0.010
← Prev2 / 3Next →