Ida
Vendor:
First CVE: Feb 21, 2011 · Active for 15 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ida over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2011
15 years ago
Most Recent CVE
May 9, 2026
76 days ago
CVE Severity & Scoring
Ida10 CVEs
40%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (20.0%)
Network0 (0.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High1 (10.0%)
Unknown8 (80.0%)
User Interaction
None0 (0.0%)
Unknown8 (80.0%)
Required2 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (20.0%)
Unknown8 (80.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4783HIGH The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_ | Dec 27, 2011 | 9.3 | 28 | NO | NO |
CVE-2011-1051HIGH Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | Feb 21, 2011 | 10.0 | 28 | NO | NO |
CVE-2011-1050HIGH Unspecified vulnerability in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to "converson of string encodings" and "inconsistencies in the handling of U | Feb 21, 2011 | 10.0 | 28 | NO | NO |
CVE-2026-45181MEDIUM Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins direc | May 9, 2026 | 6.5 | 27 | NO | NO |
CVE-2011-1054HIGH Unspecified vulnerability in the PEF input file loader in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors. | Feb 21, 2011 | 10.0 | 27 | NO | NO |
CVE-2011-1052HIGH Integer overflow in the PSX/GEOS input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | Feb 21, 2011 | 10.0 | 27 | NO | NO |
CVE-2014-9458HIGH Heap-based buffer overflow in the GDB debugger module in Hex-Rays IDA Pro before 6.6 cumulative fix 2014-12-24 allows remote GDB servers to have unspecified impact via unknown vect | Jan 2, 2015 | 10.0 | 25 | NO | NO |
CVE-2011-1049MEDIUM Buffer overflow in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbi | Feb 21, 2011 | 6.8 | 21 | NO | NO |
CVE-2022-32441MEDIUM A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write | Jul 7, 2022 | 5.5 | 20 | NO | NO |
CVE-2011-1053MEDIUM Unspecified vulnerability in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (out-of-memory exceptio | Feb 21, 2011 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Ida
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.6 | 1 | 5.5 | 0.6% | 0 | 0 |
| 6.0 | 6 | 8.5 | 1.8% | 0 | 0 |
| 5.7 | 6 | 8.5 | 1.8% | 0 | 0 |