Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
183 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file. | |
| Modificada | Media (5.5) | 1.4% | — | Radare2 | 22/5/2018 | 17/6/2026 | The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 0.89% | — | Radare2 | 17/4/2018 | 17/6/2026 | In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier. | |
| Modificada | Media (5.5) | 0.89% | — | Radare2 | 17/4/2018 | 17/6/2026 | In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 13/11/2017 | 17/6/2026 | In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c. | |
| Modificada | Media (5.5) | 1.2% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c. | |
| Modificada | Alta (7.8) | 0.98% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search. | |
| Modificada | Alta (7.8) | 1.0% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory. | |
| Modificada | Alta (7.8) | 1.2% | — | Radare2 | 27/10/2017 | 17/6/2026 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems. | |
| Modificada | Alta (7.8) | 1.2% | — | Radare2 | 27/10/2017 | 17/6/2026 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems. | |
| Modificada | Alta (7.8) | 1.1% | — | Radare2 | 16/10/2017 | 17/6/2026 | The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file. | |
| Modificada | Alta (7.8) | 1.3% | — | Radare2 | 16/10/2017 | 17/6/2026 | The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call. | |
| Modificada | Alta (7.8) | 1.9% | — | Radare2 | 5/7/2017 | 17/6/2026 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function… | |
| Modificada | Alta (7.8) | 1.8% | — | Radare2 | 26/6/2017 | 17/6/2026 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02. | |
| Modificada | Alta (7.5) | 4.1% | — | Radare2 | 19/6/2017 | 17/6/2026 | The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array. | |
| Modificada | Media (5.5) | 1.0% | — | Radare2 | 19/6/2017 | 17/6/2026 | The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.4% | — | Radare2 | 19/6/2017 | 17/6/2026 | The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 8/6/2017 | 17/6/2026 | The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file. | |
| Modificada | Media (5.5) | 0.88% | — | Radare2 | 18/4/2017 | 17/6/2026 | The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 13/4/2017 | 17/6/2026 | The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file. |