In radare2 2.4.0, there is a heap-based buffer over-read in the rasmdisassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8808.json"