Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.
Radare2 has a division by zero vulnerability in Mach-O parser's rebasebuffer function. This allow attackers to create malicious inputs that can cause denial of service.
Radare2 has a use-after-free vulnerability in pyc parser's getnoneobject function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.
A heap buffer overflow vulnerability in the rasmswfdisass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
An out-of-bounds read in radare2 v.5.8.9 and before exists in the printinsn32 function of libr/arch/p/nds32/nds32-dis.h.
An out-of-bounds read in radare2 v.5.8.9 and before exists in the printinsn32fpu function of libr/arch/p/nds32/nds32-dis.h.
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.
radare2 is vulnerable to Out-of-bounds Read
Out-of-bounds read in rbinnegetrelocs function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Out-of-bounds Read in rbinnegetentrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.
A double free issue was discovered in radare2 in cmdinfo.c:cmdinfo(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
Use After Free in NPM radare2.js prior to 5.6.2.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parsedie function.
In radare2 through 4.0, there is an integer overflow for the variable newtokensize in the function rasmmassemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted input.
In radare2 before 3.7.0, a command injection vulnerability exists in binsymbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
In radare2 through 3.5.1, there is a heap-based buffer over-read in the regglangparsechar function of egglang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c.
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in storeversioninfognuverdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in storeversioninfognuverneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.
In radare 2.0.1, an out-of-bounds read vulnerability exists in stringscanrange() in libr/bin/bin.c when doing a string search.
There is a use after free in radare2 2.6.0 in ranalbbfree() in libr/anal/bb.c via a crafted Java binary file.
There is a heap out of bounds read in radare2 2.6.0 in javaswitchop() in libr/anal/p/analjava.c via a crafted Java binary file.
The grubmemmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02.