Vulnerabilities
Vulnerable Software
Radare:  >> Radare2  >> 2.5.0  Security Vulnerabilities
The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-07-12
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
CVSS Score
5.5
EPSS Score
0.003
Published
2018-05-22
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
CVSS Score
7.8
EPSS Score
0.002
Published
2018-05-22
The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.
CVSS Score
5.5
EPSS Score
0.002
Published
2018-05-22


Contact Us

Shodan ® - All rights reserved