Skip to content
Noroxi

radare records

181 published records for vendor radare.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
28.2%
Median publish → KEV
No record has entered KEV

All records

181 records
  • A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute ar

    CriticalCVSS 9.8No exploitEPSS 3%

    radare · radare2-extrasJul 14, 2021

  • Out-of-bounds Write in radare2

    CriticalCVSS 10.0No exploitEPSS 1%

    radare · radare2Feb 28, 2025

  • Buffer Overflow and Potential Code Execution in Radare2

    CriticalCVSS 10.0No exploitEPSS 0%

    radare · radare2Mar 3, 2025

  • CVE-2022-0559
    39Monitor

    Use After Free in radareorg/radare2

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Feb 16, 2022

  • CVE-2022-0139
    39Monitor

    Use After Free in radareorg/radare2

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Feb 8, 2022

  • CVE-2023-4322
    39Monitor

    Heap-based Buffer Overflow in radareorg/radare2

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Aug 14, 2023

  • Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Dec 17, 2024

  • An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Oct 27, 2023

  • An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

    CriticalCVSS 9.8No exploitEPSS 1%

    radare · radare2Oct 27, 2023

  • CVE-2026-6942
    38Monitor

    radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass

    CriticalCVSS 9.3No exploitEPSS 3%

    radare · radare2 mcp serverApr 23, 2026

  • Command injection in Radare2

    CriticalCVSS 9.6No exploitEPSS 2%

    radare · radare2Jul 20, 2020

  • CVE-2022-1899
    36Monitor

    Out-of-bounds Read in radareorg/radare2

    CriticalCVSS 9.1No exploitEPSS 1%

    radare · radare2May 26, 2022

  • A double free issue was discovered in radare2 in cmd_info.c:cmd_info().

    CriticalCVSS 9.1No exploitEPSS 1%

    radare · radare2Aug 19, 2022

  • CVE-2022-1297
    36Monitor

    Out-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2

    CriticalCVSS 9.1No exploitEPSS 1%

    radare · radare2Apr 11, 2022

  • CVE-2022-1296
    36Monitor

    Out-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2

    CriticalCVSS 9.1No exploitEPSS 1%

    radare · radare2Apr 11, 2022

  • Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function.

    CriticalCVSS 9.1No exploitEPSS 1%

    radare · radare2Jul 7, 2023

  • CVE-2023-5686
    35Monitor

    Heap-based Buffer Overflow in radareorg/radare2

    HighCVSS 8.8No exploitEPSS 1%

    radare · radare2Oct 20, 2023

  • radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names

    HighCVSS 8.4No exploitEPSS 2%

    radare · radare2Apr 22, 2026

  • radare2 < 6.1.4 Command Injection via PDB Parser print_gvars()

    HighCVSS 8.4No exploitEPSS 2%

    radare · radare2Apr 15, 2026

  • radare2 Command Injection via DWARF Parameter Names

    HighCVSS 8.5No exploitEPSS 1%

    radare · radare2Apr 17, 2026

  • CVE-2026-8695
    34Monitor

    radare2 6.1.5 Use-After-Free via gdbr_threads_list()

    HighCVSS 8.7No exploitEPSS 1%

    radare · radare2May 15, 2026

  • CVE-2026-8696
    34Monitor

    radare2 6.1.5 Use-After-Free via gdbr_pids_list()

    HighCVSS 8.7No exploitEPSS 1%

    radare · radare2May 15, 2026

  • In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.

    HighCVSS 7.8Proof of conceptEPSS 4%

    radare · radare2Aug 7, 2019

  • In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c.

    HighCVSS 7.8No exploitEPSS 3%

    radare · radare2Dec 4, 2019

  • In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.

    HighCVSS 7.8No exploitEPSS 2%

    radare · radare2Sep 23, 2019