CVE-2026-6941
- EPSS 0.03%
- Veröffentlicht 23.04.2026 20:39:48
- Zuletzt bearbeitet 27.04.2026 14:57:19
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt ...
CVE-2026-6940
- EPSS 0.02%
- Veröffentlicht 23.04.2026 20:26:36
- Zuletzt bearbeitet 27.04.2026 14:56:28
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers c...
CVE-2026-40517
- EPSS 0.03%
- Veröffentlicht 22.04.2026 21:44:12
- Zuletzt bearbeitet 27.04.2026 17:04:26
radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can i...
CVE-2026-41015
- EPSS 0.01%
- Veröffentlicht 16.04.2026 02:35:47
- Zuletzt bearbeitet 17.04.2026 15:38:09
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less ...
CVE-2026-40499
- EPSS 0.03%
- Veröffentlicht 15.04.2026 02:05:20
- Zuletzt bearbeitet 01.05.2026 15:20:01
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can cr...
CVE-2025-63744
- EPSS 0.04%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 19.11.2025 19:03:17
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.
CVE-2025-63745
- EPSS 0.03%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 19.11.2025 19:01:27
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed dat...
CVE-2025-60360
- EPSS 0.02%
- Veröffentlicht 17.10.2025 14:15:47
- Zuletzt bearbeitet 23.10.2025 12:34:14
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
CVE-2025-60359
- EPSS 0.02%
- Veröffentlicht 17.10.2025 14:15:46
- Zuletzt bearbeitet 23.10.2025 12:34:03
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
CVE-2025-60361
- EPSS 0.02%
- Veröffentlicht 17.10.2025 00:00:00
- Zuletzt bearbeitet 23.10.2025 12:35:50
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.