VYPR
Vendor

Busybox

Products
12
CVEs
56
Across products
75
Status
Private

Products

12

Recent CVEs

56
View all 56 CVEs →
  • CVE-2016-2148CriFeb 9, 2017
    risk 0.66cvss 9.8epss 0.27

    Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.

  • CVE-2025-12220CriOct 25, 2025
    risk 0.64cvss 9.8epss 0.00

    Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2022-48174CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

  • CVE-2021-42377CriNov 15, 2021
    risk 0.64cvss 9.8epss 0.03

    An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered…

  • CVE-2018-1000517CriJun 26, 2018
    risk 0.59cvss 9.8epss 0.33

    BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectivity. This vulnerability…

  • CVE-2017-16544HigNov 20, 2017
    risk 0.58cvss 8.8epss 0.06

    In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially…

  • CVE-2025-12221HigOct 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2022-28391HigApr 3, 2022
    risk 0.57cvss 8.8epss 0.03

    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

  • CVE-2023-39810HigAug 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

  • CVE-2022-30065HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

  • CVE-2026-26157HigFeb 11, 2026
    risk 0.49cvss 7.0epss 0.01

    A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file…

  • CVE-2021-28831HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.03

    decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

  • CVE-2019-5747HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to…

  • CVE-2018-20679HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification…

  • CVE-2011-5325HigAug 7, 2017
    risk 0.49cvss 7.5epss 0.07

    Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

  • CVE-2016-2147HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.08

    Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

  • CVE-2021-42386HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

  • CVE-2021-42385HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

  • CVE-2021-42384HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

  • CVE-2021-42383HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function