CVE-2026-100505
- EPSS 0.12%
- Veröffentlicht 26.09.2026 00:36:33
- Zuletzt bearbeitet 08.10.2026 16:24:25
Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can craft malicious b...
CVE-2026-100504
- EPSS 0.13%
- Veröffentlicht 26.09.2026 00:36:32
- Zuletzt bearbeitet 08.10.2026 16:30:04
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequ...
CVE-2026-100503
- EPSS 0.12%
- Veröffentlicht 26.09.2026 00:36:31
- Zuletzt bearbeitet 08.10.2026 16:43:21
Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that...
CVE-2026-96273
- EPSS 0.12%
- Veröffentlicht 23.09.2026 00:29:51
- Zuletzt bearbeitet 28.09.2026 17:17:53
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, whe...
CVE-2026-54389
- EPSS -
- Veröffentlicht 20.08.2026 22:17:21
- Zuletzt bearbeitet 24.09.2026 20:43:32
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserializa...
CVE-2026-18718
- EPSS 0.21%
- Veröffentlicht 03.08.2026 16:54:17
- Zuletzt bearbeitet 24.09.2026 20:44:42
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the ...
CVE-2026-52759
- EPSS 0.15%
- Veröffentlicht 10.06.2026 12:43:09
- Zuletzt bearbeitet 11.06.2026 13:28:01
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command co...
CVE-2026-52758
- EPSS 0.31%
- Veröffentlicht 10.06.2026 12:42:30
- Zuletzt bearbeitet 14.07.2026 22:17:14
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query ...
CVE-2026-52757
- EPSS 0.14%
- Veröffentlicht 10.06.2026 12:42:01
- Zuletzt bearbeitet 14.07.2026 22:17:14
Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighI...
CVE-2026-52756
- EPSS 0.46%
- Veröffentlicht 10.06.2026 12:41:39
- Zuletzt bearbeitet 14.07.2026 22:17:14
Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation. Remote attackers can connect ...