« Volver al listado

NSA

NSA Ghidra: vulnerabilidades y CVE

NSA Ghidra tiene 28 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE28
Últimos 12 meses22
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100505Media (4.8)0.12%—25 sept 2026
Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length.…
CVE-2026-100504Alta (7.3)0.13%—25 sept 2026
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries…
CVE-2026-100503Media (4.8)0.12%—25 sept 2026
Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with…
CVE-2026-96273Media (6.8)0.10%—22 sept 2026
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious…
CVE-2026-54389Media (6.7)0.18%—20 ago 2026
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters…
CVE-2026-18718Alta (7.1)0.17%—3 ago 2026
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory…
CVE-2026-52759Media (6.7)0.16%—10 jun 2026
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an…
CVE-2026-52758Alta (8.7)0.56%—10 jun 2026
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary…
CVE-2026-52757Media (4.6)0.15%—10 jun 2026
Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that…
CVE-2026-52756Media (6.3)0.60%—10 jun 2026
Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without…
CVE-2026-52755Alta (8.4)0.22%—10 jun 2026
Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files…
CVE-2026-52754Alta (8.7)0.45%—10 jun 2026
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public…
CVE-2026-52753Media (6.7)0.16%—10 jun 2026
Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to…
CVE-2026-52752Alta (8.4)0.22%—10 jun 2026
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like…
CVE-2026-52751Alta (8.6)1.1%—10 jun 2026
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with…
CVE-2026-52750Alta (8.4)0.74%—10 jun 2026
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's…
CVE-2026-49498Alta (8.7)0.47%—10 jun 2026
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements.…
CVE-2026-49497Media (4.6)0.19%—10 jun 2026
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft…
CVE-2026-49496Media (6.9)0.18%—10 jun 2026
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can…
CVE-2026-49495Media (6.7)0.16%—10 jun 2026
Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular…
CVE-2024-58350Baja (2.1)0.11%—10 jun 2026
Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers…
CVE-2026-4946Alta (8.8)0.77%—29 mar 2026
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the…
CVE-2023-22671Crítica (9.8)2.9%—6 ene 2023
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
CVE-2019-17665Alta (7.8)0.49%—16 oct 2019
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.
CVE-2019-17664Alta (7.8)0.43%—16 oct 2019
NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the…
CVE-2019-16941Crítica (9.8)5.1%—28 sept 2019
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in…
CVE-2019-13625Crítica (9.1)2.4%—17 jul 2019
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
CVE-2019-13623Alta (7.8)5.0%—17 jul 2019
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution10
  2. T1059 Command and Scripting Interpreter5
  3. T1005 Data from Local System3
  4. T1210 Exploitation of Remote Services3
  5. T1499.004 Application or System Exploitation2
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de NSA