CVE-2018-14016 is a heap-based buffer over-read vulnerability in radare2 version 2.7.0, specifically within the r_bin_mdmp_init_directory_entry function, affecting the radare2 reverse engineering framework. It carries a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring user interaction (UI:R) to trigger a denial of service (application crash) via a crafted Mini Crash Dump file. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.0CPE matchmatch criteria | cpe:2.3:a:radare:radare2:2.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.