📦 Radare2

by Radare

🔍 What is Radare2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1864

CRITICAL CVSS 9.8 Mar 3, 2025

CVE-2025-1864 is a memory buffer overflow vulnerability in radare2, a reverse engineering framework. Attackers can exploit this to execute arbitrary code or cause denial of service. Users running rada...

CVE-2025-1744

CRITICAL CVSS 9.8 Feb 28, 2025

CVE-2025-1744 is an out-of-bounds write vulnerability in radare2 that allows heap-based buffer over-read or buffer overflow. This affects all users running radare2 versions before 5.9.9. Attackers cou...

CVE-2024-29646

CRITICAL CVSS 9.8 Dec 17, 2024

A buffer overflow vulnerability in radare2 v5.8.8 allows attackers to execute arbitrary code by manipulating name, type, or group fields. This affects users of radare2 reverse engineering framework. S...

CVE-2023-46569

CRITICAL CVSS 9.8 Oct 28, 2023

CVE-2023-46569 is an out-of-bounds read vulnerability in radare2's ND32 disassembler that could allow attackers to read sensitive memory contents or cause application crashes. This affects radare2 use...

CVE-2023-4322

CRITICAL CVSS 9.8 Aug 14, 2023

A heap-based buffer overflow vulnerability in radare2 versions prior to 5.9.0 allows attackers to execute arbitrary code or cause denial of service. This affects users of the radare2 reverse engineeri...

CVE-2021-32494

CRITICAL CVSS 10.0 Jul 7, 2023

CVE-2021-32494 is a division by zero vulnerability in Radare2's Mach-O parser that allows attackers to cause denial of service through malicious inputs. This affects users who process untrusted Mach-O...

CVE-2022-1899

CRITICAL CVSS 9.1 May 26, 2022

CVE-2022-1899 is an out-of-bounds read vulnerability in radare2, a popular reverse engineering framework. This vulnerability allows attackers to read memory beyond allocated buffers, potentially expos...

CVE-2022-1297

CRITICAL CVSS 9.1 Apr 11, 2022

CVE-2022-1297 is an out-of-bounds read vulnerability in the r_bin_ne_get_entrypoints function of radare2, a reverse engineering framework. Attackers can exploit this to read sensitive memory contents ...

CVE-2022-0559

CRITICAL CVSS 9.8 Feb 16, 2022

This is a use-after-free vulnerability in radare2, a popular reverse engineering framework. Attackers can exploit this to execute arbitrary code or cause denial of service by manipulating freed memory...

CVE-2022-0139

CRITICAL CVSS 9.8 Feb 8, 2022

CVE-2022-0139 is a use-after-free vulnerability in radare2, a popular reverse engineering framework. This allows attackers to execute arbitrary code or cause denial of service by exploiting memory cor...

CVE-2024-29645

HIGH CVSS 7.8 Dec 2, 2024

A buffer overflow vulnerability in radare2 v5.8.8 allows attackers to execute arbitrary code by exploiting the parse_die function. This affects users running vulnerable versions of the radare2 reverse...

CVE-2023-47016

HIGH CVSS 7.5 Nov 22, 2023

CVE-2023-47016 is an out-of-bounds read vulnerability in radare2's binary object handling that can cause application crashes. Attackers could potentially exploit this to read sensitive memory contents...

CVE-2022-28068

HIGH CVSS 7.5 Aug 22, 2023

CVE-2022-28068 is a heap buffer overflow vulnerability in the r_sleb128 function of radare2, a popular reverse engineering framework. Attackers can exploit this by providing specially crafted input to...

CVE-2022-28070

HIGH CVSS 7.5 Aug 22, 2023

A null pointer dereference vulnerability in radare2's __core_anal_fcn function allows attackers to cause denial of service or potentially execute arbitrary code by crashing the application. This affec...

CVE-2022-28072

HIGH CVSS 7.5 Aug 22, 2023

A heap buffer overflow vulnerability in the r_read_le32 function of radare2 versions 5.4.2 and 5.4.0 allows attackers to execute arbitrary code or cause denial of service. This affects users who proce...

CVE-2022-1809

HIGH CVSS 7.8 May 21, 2022

CVE-2022-1809 is an uninitialized pointer access vulnerability in radare2 reverse engineering framework versions before 5.7.0. This allows attackers to potentially execute arbitrary code or cause deni...

CVE-2022-1714

HIGH CVSS 7.1 May 13, 2022

CVE-2022-1714 is an out-of-bounds read vulnerability in radare2 reverse engineering framework versions prior to 5.7.0. This allows attackers to read sensitive information from adjacent memory location...

CVE-2022-1451

HIGH CVSS 7.1 Apr 24, 2022

This vulnerability in radare2 allows attackers to read memory beyond intended buffer boundaries in the Java constant value attribute parsing function. It affects users of radare2 versions prior to 5.7...

CVE-2022-1437

HIGH CVSS 7.1 Apr 22, 2022

CVE-2022-1437 is a heap-based buffer overflow vulnerability in radare2 reverse engineering framework versions prior to 5.7.0. This allows attackers to read sensitive information from adjacent memory l...

CVE-2022-1240

HIGH CVSS 7.8 Apr 6, 2022

A heap buffer overflow vulnerability in radare2's Mach-O binary format parser allows attackers to execute arbitrary code or cause denial of service. This affects users of radare2 reverse engineering f...

CVE-2022-1238

HIGH CVSS 7.8 Apr 6, 2022

This vulnerability is a heap buffer overflow in radare2's NE file format parser that allows writing beyond allocated memory boundaries. Attackers could exploit this to execute arbitrary code or crash ...

CVE-2022-1031

HIGH CVSS 7.8 Mar 22, 2022

This is a use-after-free vulnerability in the op_is_set_bp function of radare2, a reverse engineering framework. Attackers could exploit this to execute arbitrary code or cause denial of service by ma...

CVE-2022-0713

HIGH CVSS 7.1 Feb 22, 2022

CVE-2022-0713 is a heap-based buffer overflow vulnerability in radare2 reverse engineering framework versions prior to 5.6.4. Attackers can exploit this by providing specially crafted input to cause m...

CVE-2022-0676

HIGH CVSS 7.8 Feb 22, 2022

This CVE describes a heap-based buffer overflow vulnerability in radare2, a popular reverse engineering framework. Attackers can exploit this by providing specially crafted input to cause memory corru...

CVE-2025-63745

MEDIUM CVSS 5.5 Nov 14, 2025

A NULL pointer dereference vulnerability in radare2 versions 6.0.5 and earlier allows attackers to cause a denial of service via a segmentation fault. This affects users who process untrusted binary f...

CVE-2025-63744

MEDIUM CVSS 4.3 Nov 14, 2025

A NULL pointer dereference vulnerability in radare2's bin_dyldcache.c load() function allows attackers to crash the program by processing a malicious file. This affects radare2 versions 6.0.5 and earl...

CVE-2025-60360

MEDIUM CVSS 5.5 Oct 17, 2025

CVE-2025-60360 is a memory leak vulnerability in radare2's r2r_subprocess_init function that allows attackers to cause resource exhaustion through repeated exploitation. This affects users running rad...

CVE-2025-60359

MEDIUM CVSS 5.5 Oct 17, 2025

CVE-2025-60359 is a memory leak vulnerability in radare2's r_bin_object_new function that allows attackers to cause denial of service through resource exhaustion. This affects users of radare2 reverse...

CVE-2025-60358

MEDIUM CVSS 5.5 Oct 16, 2025

A memory leak vulnerability exists in radare2's _load_relocations function in versions 5.9.8 and earlier. This vulnerability allows attackers to cause resource exhaustion by repeatedly triggering the ...

CVE-2024-48241

MEDIUM CVSS 5.5 Oct 30, 2024

A local denial-of-service vulnerability in radare2's __bf_div function allows attackers to crash the application. This affects users running radare2 versions 5.8.0 through 5.9.4. The vulnerability req...