Home/Product/rizin
Product

rizin

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31053
all versions
A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed o
6.2MEDIUM
CVE-2026-22780
< 0.8.2
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when
4.4MEDIUM
CVE-2025-1788
<= 0.8.0
A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_enco
5.3MEDIUM
CVE-2025-1786
< 0.8.0
A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream
5.3MEDIUM
CVE-2024-31668
< 0.6.3
rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.
9.1CRITICAL
CVE-2024-31670
< 0.6.3
rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions i
6.3MEDIUM
CVE-2024-31669
< 0.6.3
rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, an
7.5HIGH
CVE-2023-40022
< 0.6.1
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to integer ov
7.8HIGH
CVE-2023-30226
< 0.5.0
An issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to cause a den
5.5MEDIUM
CVE-2021-3674
<= 0.2.1
A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. C
7.8HIGH
CVE-2023-27590
<= 0.5.1
Rizin is a UNIX-like reverse engineering framework and command-line toolset. In version 0.5.1 and prior, converting a GDB register
7.8HIGH
CVE-2022-36044
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-
7.8HIGH
CVE-2022-36043
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to a double f
7.8HIGH
CVE-2022-36041
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-
7.8HIGH
CVE-2022-36040
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-
7.8HIGH
CVE-2022-36042
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-
7.8HIGH
CVE-2022-36039
<= 0.4.0
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to out-of-bou
7.8HIGH
CVE-2021-4022
<= 0.3.1
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binaryget
5.5MEDIUM
CVE-2022-34612
<= 0.4.0
Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerability allows
5.5MEDIUM
CVE-2021-43814
<= 0.3.1
Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap
7.7HIGH
threatengine.sh