VendorsRadareradare2all versions
Vulnerabilities

Radare 2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

170CVEs
CVE-2018-8808
In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
Published 2018-03-20 · Modified
5.5EPSS 0.011
CVE-2017-7854
The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
Published 2017-04-13 · Modified
5.5EPSS 0.011
CVE-2017-9520
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
Published 2017-06-08 · Modified
5.5EPSS 0.011
CVE-2018-20460
In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
Published 2018-12-25 · Modified
5.5EPSS 0.011
CVE-2017-6387
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
Published 2017-03-02 · Modified
5.5EPSS 0.011
CVE-2018-20455
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.
Published 2018-12-25 · Modified
5.5EPSS 0.011
CVE-2017-16805
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.
Published 2017-11-13 · Modified
5.5EPSS 0.010
CVE-2018-20461
In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.
Published 2018-12-25 · Modified
5.5EPSS 0.010
CVE-2017-9762
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
Published 2017-06-19 · Modified
5.5EPSS 0.010
CVE-2018-20456
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.
Published 2018-12-25 · Modified
5.5EPSS 0.010
CVE-2020-16269
radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.
Published 2020-08-03 · Modified
5.5EPSS 0.010
CVE-2018-19842
getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
Published 2018-12-04 · Modified
5.5EPSS 0.010
CVE-2021-44975
radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.
Published 2022-05-24 · Modified
5.5EPSS 0.010
CVE-2018-19843
opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
Published 2018-12-04 · Modified
5.5EPSS 0.010
CVE-2018-15834
In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.
Published 2018-09-12 · Modified
5.5EPSS 0.010
CVE-2018-20458
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2018-20459
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2019-12865
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
Published 2019-06-17 · Modified
5.5EPSS 0.009
CVE-2018-11380
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
Published 2018-05-22 · Modified
5.5EPSS 0.009
CVE-2018-11381
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Published 2018-05-22 · Modified
5.5EPSS 0.009
CVE-2018-10187
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier.
Published 2018-04-17 · Modified
5.5EPSS 0.009
CVE-2018-10186
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.
Published 2018-04-17 · Modified
5.5EPSS 0.009
CVE-2017-7946
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
Published 2017-04-18 · Modified
5.5EPSS 0.009
CVE-2021-44974
radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.
Published 2022-05-25 · Modified
5.5EPSS 0.009
CVE-2018-20457
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
Published 2018-12-25 · Modified
5.5EPSS 0.009
CVE-2018-12322
There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.
Published 2018-06-13 · Modified
5.5EPSS 0.009
CVE-2017-7716
The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
Published 2017-04-12 · Modified
5.5EPSS 0.007
CVE-2023-27114
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
Published 2023-03-10 · Modified
5.5EPSS 0.003
CVE-2022-34502
Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.
Published 2022-07-22 · Modified
5.5EPSS 0.003
CVE-2022-34520
Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
Published 2022-07-22 · Modified
5.5EPSS 0.003
CVE-2024-26475
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
Published 2024-03-14 · Modified
5.5EPSS 0.003
CVE-2024-48241
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
Published 2024-10-30 · Analyzed
5.5EPSS 0.002
CVE-2026-14758
radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow
Published 2026-07-05 · Analyzed
5.5EPSS 0.002
CVE-2026-14761
radareorg radare2 str.c r_str_append integer overflow
Published 2026-07-05 · Analyzed
5.5EPSS 0.002
CVE-2026-14786
radareorg radare2 str.c r_str_word_get0set integer overflow
Published 2026-07-06 · Analyzed
5.5EPSS 0.002
CVE-2025-60359
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
Published 2025-10-17 · Analyzed
5.5EPSS 0.002
CVE-2025-60360
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
Published 2025-10-17 · Analyzed
5.5EPSS 0.002
CVE-2025-60358
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
Published 2025-10-16 · Analyzed
5.5EPSS 0.002
CVE-2025-63745
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.
Published 2025-11-14 · Analyzed
5.5EPSS 0.002
CVE-2025-1378
radare2 rasm2 rasm2.c memory corruption
Published 2025-02-17 · Analyzed
4.8EPSS 0.003
← Prev4 / 5Next →