Skip to main content

Vendor archive

radare CVEs

Beta · best-effort

172 CVEs tagged to vendor radare16 Critical, 65 High, 73 Medium, 18 Low, 0 Unrated.

CVE-2025-5646

Published Jun 5, 2025

A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the c…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5645

Published Jun 5, 2025

A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5644

Published Jun 5, 2025

A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function r_cons_flush in the library /libr/cons/cons.c of the…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5643

Published Jun 5, 2025

A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the library /libr/cons/cons.c of the compon…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5642

Published Jun 5, 2025

A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The m…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5641

Published Jun 5, 2025

A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_breaked in the library /libr/cons/cons.c of the component r…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1864

Published Mar 3, 2025

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1744

Published Feb 28, 2025

Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1378

Published Feb 17, 2025

A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. T…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-29646

Published Dec 17, 2024

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11858

Published Dec 15, 2024

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted i…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29645

Published Dec 2, 2024

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48241

Published Oct 30, 2024

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26475

Published Mar 14, 2024

An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47016

Published Nov 22, 2023

radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46570

Published Oct 28, 2023

An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46569

Published Oct 28, 2023

An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28073

Published Aug 22, 2023

A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28072

Published Aug 22, 2023

A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28071

Published Aug 22, 2023

A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28070

Published Aug 22, 2023

A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28068

Published Aug 22, 2023

A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 172 CVEsPage 2 of 7