CVE detail
CVE-2019-14745 — CVE-2019-14745
Published 2019-08-07 · Modified 2026-06-17 · Vendor radare · Product radare2 · Source nvd
HIGH
severity
CVSS-derived band
0.0441
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References