Vulnerability index

Browse CVEs

137 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Radare2 MEDIUM 5.5
CVE-2022-1382

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affec…

Fix: 5.6.8+
Fix from $1,600 2022-04-18
Radare2 CRITICAL 9.1
CVE-2022-1296

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to…

Fix: 5.6.8+
Fix from $2,300 2022-04-11
Radare2 CRITICAL 9.1
CVE-2022-1297

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers…

Fix: 5.6.8+
Fix from $2,300 2022-04-11
Radare2 MEDIUM 5.5
CVE-2022-1284

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

Fix: 5.6.8+
Fix from $1,600 2022-04-08
Radare2 MEDIUM 5.5
CVE-2022-1283

NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attack…

Fix: 5.6.8+
Fix from $1,600 2022-04-08
Radare2 HIGH 7.8
CVE-2022-1240

Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during …

Fix: after 5.6.6
Fix from $1,950 2022-04-06
Radare2 HIGH 7.8
CVE-2022-1237

Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable.…

Fix: 5.6.8+
Fix from $1,950 2022-04-06
Radare2 HIGH 7.8
CVE-2022-1238

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be …

Fix: 5.6.8+
Fix from $1,950 2022-04-06
Radare2 MEDIUM 5.5
CVE-2022-1244

heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

Fix: 5.6.8+
Fix from $1,600 2022-04-05
Radare2 MEDIUM 6.6
CVE-2022-1207

Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outs…

Fix: 5.6.8+
Fix from $1,600 2022-04-01
Radare2 MEDIUM 5.5
CVE-2022-1052

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

Fix: 5.6.6+
Fix from $1,600 2022-03-24
Radare2 HIGH 7.5
CVE-2022-1061

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

Fix: 5.6.8+
Fix from $1,950 2022-03-24
Radare2 HIGH 7.8
CVE-2022-1031

Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

Fix: 5.6.6+
Fix from $1,950 2022-03-22
Radare2 MEDIUM 5.5
CVE-2022-0849

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

Fix: 5.6.6+
Fix from $1,600 2022-03-05
Radare2 HIGH 7.5
CVE-2021-4021

A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary …

Fix: after 5.5.0
Fix from $1,950 2022-02-24
Radare2 CRITICAL 9.8
CVE-2022-0139

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

Fix: 5.6.0+
Fix from $2,300 2022-02-08
Radare2 Extras CRITICAL 9.8
CVE-2020-24133

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary c…

Fix: 5.1.0+
Fix from $2,300 2021-07-14
Radare2 HIGH 7.8
CVE-2019-19590

In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer …

Fix: after 4.0.0
Fix from $1,950 2019-12-05
Radare2 HIGH 7.8
CVE-2019-16718

In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss…

Fix: 3.9.0+
Fix from $1,950 2019-09-23
Radare2 MEDIUM 5.5
CVE-2019-12865

In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.

Fix: after 3.5.1
Fix from $1,600 2019-06-17
Radare2 HIGH 7.5
CVE-2019-12829

radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unsp…

Fix: after 3.5.1
Fix from $1,950 2019-06-15
Radare2 HIGH 7.8
CVE-2019-12790

In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to …

Fix: after 3.5.1
Fix from $1,950 2019-06-10
Radare2 MEDIUM 5.5
CVE-2018-20455

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application cra…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20456

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application cra…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20457

In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via a…

Fix: after 3.1.3
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20458

In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20459

In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash…

Fix: after 3.1.3
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20460

In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application cras…

Fix: 3.1.2+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20461

In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-19842

getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted …

Fix: 3.1.0+
Fix from $1,600 2018-12-04