Hex Rays maintains a narrowly focused vulnerability footprint centered on its IDA and IDA Pro reverse-engineering and binary-analysis tools, which are widely embedded in security research, vulnerability analysis, and malware investigation workflows despite their specialized purpose. The vendor's disclosures recur across this single product line; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hex Rays over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4783HIGH The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_ | Dec 27, 2011 | 9.3 | 28 | NO | NO |
CVE-2011-1051HIGH Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | Feb 21, 2011 | 10.0 | 28 | NO | NO |
CVE-2011-1050HIGH Unspecified vulnerability in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to "converson of string encodings" and "inconsistencies in the handling of U | Feb 21, 2011 | 10.0 | 28 | NO | NO |
CVE-2026-45181MEDIUM Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins direc | May 9, 2026 | 6.5 | 27 | NO | NO |
CVE-2011-1054HIGH Unspecified vulnerability in the PEF input file loader in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors. | Feb 21, 2011 | 10.0 | 27 | NO | NO |
CVE-2011-1052HIGH Integer overflow in the PSX/GEOS input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | Feb 21, 2011 | 10.0 | 27 | NO | NO |
CVE-2014-9458HIGH Heap-based buffer overflow in the GDB debugger module in Hex-Rays IDA Pro before 6.6 cumulative fix 2014-12-24 allows remote GDB servers to have unspecified impact via unknown vect | Jan 2, 2015 | 10.0 | 25 | NO | NO |
CVE-2024-44083HIGH ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry poin | Aug 19, 2024 | 7.5 | 24 | NO | NO |
CVE-2011-1049MEDIUM Buffer overflow in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbi | Feb 21, 2011 | 6.8 | 21 | NO | NO |
CVE-2022-32441MEDIUM A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write | Jul 7, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hex Rays.
Media articles that mention a CVE ID that affects a product developed by Hex Rays — matched by CVE ID, not by vendor name.