VendorsRadareradare2any version
Vulnerabilities

Radare 2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

100CVEs
CVE-2018-20456
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.
Published 2018-12-25 · Modified
5.5EPSS 0.010
CVE-2018-19842
getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
Published 2018-12-04 · Modified
5.5EPSS 0.010
CVE-2018-19843
opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
Published 2018-12-04 · Modified
5.5EPSS 0.010
CVE-2018-15834
In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.
Published 2018-09-12 · Modified
5.5EPSS 0.010
CVE-2018-20458
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2018-20459
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2019-12865
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
Published 2019-06-17 · Modified
5.5EPSS 0.009
CVE-2021-44974
radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.
Published 2022-05-25 · Modified
5.5EPSS 0.009
CVE-2018-20457
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2024-26475
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
Published 2024-03-14 · Modified
5.5EPSS 0.003
CVE-2024-48241
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
Published 2024-10-30 · Analyzed
5.5EPSS 0.002
CVE-2026-14758
radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow
Published 2026-07-05 · Analyzed
5.5EPSS 0.002
CVE-2026-14761
radareorg radare2 str.c r_str_append integer overflow
Published 2026-07-05 · Analyzed
5.5EPSS 0.002
CVE-2026-14786
radareorg radare2 str.c r_str_word_get0set integer overflow
Published 2026-07-06 · Analyzed
5.5EPSS 0.002
CVE-2025-60360
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
Published 2025-10-17 · Analyzed
5.5EPSS 0.002
CVE-2025-60359
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
Published 2025-10-17 · Analyzed
5.5EPSS 0.002
CVE-2025-60358
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
Published 2025-10-16 · Analyzed
5.5EPSS 0.002
CVE-2025-63745
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.
Published 2025-11-14 · Analyzed
5.5EPSS 0.002
CVE-2025-63744
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.
Published 2025-11-14 · Analyzed
4.3EPSS 0.003
CVE-2025-60361
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
Published 2025-10-17 · Analyzed
3.3EPSS 0.002
← Prev3 / 3