radare

9 records · 9 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names radare as an affected vendor, highest CVSS first.

  1. MEDIUM 5.5CVE-2026-81886public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as t…

    radare2

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.5CVE-2026-81885public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection…

    radare2

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.5CVE-2026-81880public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of section…

    radare2

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.5CVE-2026-81879public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still …

    radare2

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.5CVE-2026-81878public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overf…

    radare2

    AI risk analysis on Exploit-DB.ai →

  6. LOW 3.3CVE-2026-81883public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a functi…

    radare2

    AI risk analysis on Exploit-DB.ai →

  7. LOW 3.3CVE-2026-81882public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and di…

    radare2

    AI risk analysis on Exploit-DB.ai →

  8. LOW 3.3CVE-2026-81881public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtra…

    radare2

    AI risk analysis on Exploit-DB.ai →

  9. LOW 2.5CVE-2026-81884public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to b…

    radare2

    AI risk analysis on Exploit-DB.ai →