Vulnerabilities
Vulnerable Software
Nsa:  >> Ghidra  >> 10.0.1  Security Vulnerabilities
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command count value, forcing the parser to allocate excessive heap memory without validating file size, crashing the Ghidra JVM.
CVSS Score
6.7
EPSS Score
0.0
Published
2026-06-10
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
CVSS Score
9.8
EPSS Score
0.041
Published
2023-01-06


Contact Us

Shodan ® - All rights reserved