Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

radareorg/radare2 — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in radareorg/radare2, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness enumerations associated with the radareorg/radare2 reverse engineering framework, focusing on software security flaws and implementation errors. It aggregates vulnerability data spanning from the initial release of the tool up to the most recent disclosures, providing a comprehensive historical overview of its security posture. The collection includes issues related to buffer overflows, race conditions, input validation failures, and other defects that may lead to remote code execution, denial of service, or privilege escalation within the context of binary analysis and debugging operations. Readers can track the vendor's advisories to stay informed about critical patches and mitigation strategies as they are released. The page also allows users to understand the broader weakness class by examining how specific flaws manifest in this particular open-source project, offering insights into common pitfalls in low-level system programming. Additionally, one can look up the product's vulnerability history to assess its evolution over time, identifying trends in code quality and security responsiveness. This resource serves as a reference for security professionals, developers, and users who rely on radare2 for forensic analysis or malware research, helping them evaluate risks and apply appropriate safeguards. By centralizing this information, the page facilitates a clearer understanding of the security landscape surrounding this widely used reverse engineering tool, enabling more informed decision-making regarding its deployment and configuration in sensitive environments.

Vendor: radareorg

CVE IDTitleCVSSSeverityPublished
CVE-2023-5686 Heap-based Buffer Overflow in radareorg/radare2 CWE-122 7.8 -2023-10-20
CVE-2023-4322 Heap-based Buffer Overflow in radareorg/radare2 CWE-122 7.8 -2023-08-14
CVE-2023-1605 Denial of Service in radareorg/radare2 CWE-400 6.2 -2023-03-23
CVE-2023-0302 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2 CWE-75 7.8 -2023-01-15
CVE-2022-4843 NULL Pointer Dereference in radareorg/radare2 CWE-476 5.5 -2022-12-29
CVE-2022-4398 Integer Overflow or Wraparound in radareorg/radare2 CWE-190 5.5 -2022-12-10
CVE-2022-1899 Out-of-bounds Read in radareorg/radare2 CWE-125 7.7 -2022-05-26
CVE-2022-1809 Access of Uninitialized Pointer in radareorg/radare2 CWE-824 7.1 -2022-05-21
CVE-2022-1714 Out-of-bounds Read in radareorg/radare2 CWE-125 7.1 -2022-05-13
CVE-2022-1649 Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2 CWE-476 7.1 -2022-05-10
CVE-2022-1451 Out-of-bounds Read in r_bin_java_constant_value_attr_new function in radareorg/radare2 CWE-788 7.1 -2022-04-24
CVE-2022-1452 Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in radareorg/radare2 CWE-125 7.1 -2022-04-24
CVE-2022-1444 heap-use-after-free in radareorg/radare2 CWE-416 5.5 -2022-04-23
CVE-2022-1437 Heap-based Buffer Overflow in radareorg/radare2 CWE-122 7.1 -2022-04-22
CVE-2022-1383 Heap-based Buffer Overflow in radareorg/radare2 CWE-122 7.1 -2022-04-17
CVE-2022-1382 NULL Pointer Dereference in radareorg/radare2 CWE-476 5.5 -2022-04-16
CVE-2022-1297 Out-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2 CWE-125 9.1 -2022-04-11
CVE-2022-1296 Out-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2 CWE-125 8.1 -2022-04-11
CVE-2022-1284 heap-use-after-free in radareorg/radare2 CWE-416 5.5 -2022-04-08
CVE-2022-1283 NULL Pointer Dereference in r_bin_ne_get_entrypoints function in radareorg/radare2 CWE-476 5.5 -2022-04-08
CVE-2022-1240 Heap buffer overflow in libr/bin/format/mach0/mach0.c in radareorg/radare2 CWE-122 7.8 -2022-04-06
CVE-2022-1237 Improper Validation of Array Index in radareorg/radare2 CWE-129 7.8 -2022-04-06
CVE-2022-1238 Out-of-bounds Write in libr/bin/format/ne/ne.c in radareorg/radare2 CWE-787 7.8 -2022-04-06
CVE-2022-1244 heap-buffer-overflow in radareorg/radare2 CWE-122 5.5 -2022-04-05
CVE-2022-1207 Out-of-bounds read in radareorg/radare2 CWE-125 5.5 -2022-04-01
CVE-2022-1052 Heap Buffer Overflow in iterate_chained_fixups in radareorg/radare2 CWE-122 6.2 -2022-03-24
CVE-2022-1061 Heap Buffer Overflow in parseDragons in radareorg/radare2 CWE-122 6.5 -2022-03-24
CVE-2022-1031 Use After Free in op_is_set_bp in radareorg/radare2 CWE-416 7.8 -2022-03-22
CVE-2022-0849 Use After Free in r_reg_get_name_idx in radareorg/radare2 CWE-416 7.1 -2022-03-05
CVE-2022-0695 Denial of Service in radareorg/radare2 CWE-400 6.2 -2022-02-24

All 44 known CVE vulnerabilities affecting radareorg/radare2 with full Chinese analysis, references, and POCs where available.