CVE-2018-15834 describes a heap overflow vulnerability in radare2 versions prior to 2.9.0, specifically within the read_module_referenced_functions function, exploitable through a crafted flirt signature file. This medium-severity vulnerability (CVSS 5.5) requires local access and user interaction (UI:R) to trigger, potentially leading to a denial of service (A:H) but not impacting confidentiality or integrity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and it is not listed on the KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.0CPE matchmatch criteria | cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.