NSA
NSA Ghidra: vulnerabilidades y CVE
NSA Ghidra tiene 28 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses22
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100505 | Media (4.8) | 0.12% | — | 25 sept 2026 | Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length.… |
| CVE-2026-100504 | Alta (7.3) | 0.13% | — | 25 sept 2026 | Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries… |
| CVE-2026-100503 | Media (4.8) | 0.12% | — | 25 sept 2026 | Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with… |
| CVE-2026-96273 | Media (6.8) | 0.10% | — | 22 sept 2026 | Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious… |
| CVE-2026-54389 | Media (6.7) | 0.18% | — | 20 ago 2026 | Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters… |
| CVE-2026-18718 | Alta (7.1) | 0.17% | — | 3 ago 2026 | Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory… |
| CVE-2026-52759 | Media (6.7) | 0.16% | — | 10 jun 2026 | Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an… |
| CVE-2026-52758 | Alta (8.7) | 0.56% | — | 10 jun 2026 | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary… |
| CVE-2026-52757 | Media (4.6) | 0.15% | — | 10 jun 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that… |
| CVE-2026-52756 | Media (6.3) | 0.60% | — | 10 jun 2026 | Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without… |
| CVE-2026-52755 | Alta (8.4) | 0.22% | — | 10 jun 2026 | Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files… |
| CVE-2026-52754 | Alta (8.7) | 0.45% | — | 10 jun 2026 | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public… |
| CVE-2026-52753 | Media (6.7) | 0.16% | — | 10 jun 2026 | Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to… |
| CVE-2026-52752 | Alta (8.4) | 0.22% | — | 10 jun 2026 | Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like… |
| CVE-2026-52751 | Alta (8.6) | 1.1% | — | 10 jun 2026 | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with… |
| CVE-2026-52750 | Alta (8.4) | 0.74% | — | 10 jun 2026 | Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's… |
| CVE-2026-49498 | Alta (8.7) | 0.47% | — | 10 jun 2026 | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements.… |
| CVE-2026-49497 | Media (4.6) | 0.19% | — | 10 jun 2026 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft… |
| CVE-2026-49496 | Media (6.9) | 0.18% | — | 10 jun 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can… |
| CVE-2026-49495 | Media (6.7) | 0.16% | — | 10 jun 2026 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular… |
| CVE-2024-58350 | Baja (2.1) | 0.11% | — | 10 jun 2026 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers… |
| CVE-2026-4946 | Alta (8.8) | 0.77% | — | 29 mar 2026 | Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the… |
| CVE-2023-22671 | Crítica (9.8) | 2.9% | — | 6 ene 2023 | Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input. |
| CVE-2019-17665 | Alta (7.8) | 0.49% | — | 16 oct 2019 | NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory. |
| CVE-2019-17664 | Alta (7.8) | 0.43% | — | 16 oct 2019 | NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the… |
| CVE-2019-16941 | Crítica (9.8) | 5.1% | — | 28 sept 2019 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in… |
| CVE-2019-13625 | Crítica (9.1) | 2.4% | — | 17 jul 2019 | NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file. |
| CVE-2019-13623 | Alta (7.8) | 5.0% | — | 17 jul 2019 | In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.