Vendor CVEs
Busybox
All CVEs
61 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-2581 | Med | 0.28 | 4.3 | 0.01 | Mar 21, 2025 | A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. The manipulation leads to integer underflow. The attack can be launched remotely. Upgrading to version… | ||
| CVE-2026-88841 | low | 0.21 | 3.3 | — | Sep 23, 2026 | busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption | ||
| CVE-2026-38755 | Low | 0.19 | 2.9 | 0.00 | Jul 15, 2026 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | ||
| CVE-2026-38752 | Low | 0.19 | 2.9 | 0.00 | Jul 15, 2026 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | ||
| CVE-2024-58251 | Low | 0.16 | 2.5 | 0.00 | Apr 23, 2025 | In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim. | ||
| CVE-2026-76014 | Low | 0.14 | 3.3 | 0.00 | Aug 19, 2026 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to… | ||
| CVE-2025-46394 | Low | 0.14 | 3.2 | 0.00 | Apr 23, 2025 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. | ||
| CVE-2013-1813 | 0.00 | — | 0.01 | Nov 23, 2013 | util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors. | |||
| CVE-2011-2716 | 0.00 | — | 0.02 | Jul 3, 2012 | The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options. | |||
| CVE-2006-5050 | 0.00 | — | 0.02 | Sep 27, 2006 | Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI. | |||
| CVE-2000-0354 | 0.00 | — | 0.02 | Sep 28, 2000 | mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory. |
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. The manipulation leads to integer underflow. The attack can be launched remotely. Upgrading to version…
- risk 0.21cvss 3.3epss —
busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption
- risk 0.19cvss 2.9epss 0.00
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- risk 0.19cvss 2.9epss 0.00
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
- risk 0.16cvss 2.5epss 0.00
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
- risk 0.14cvss 3.3epss 0.00
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to…
- risk 0.14cvss 3.2epss 0.00
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
- CVE-2013-1813Nov 23, 2013risk 0.00cvss —epss 0.01
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
- CVE-2011-2716Jul 3, 2012risk 0.00cvss —epss 0.02
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
- CVE-2006-5050Sep 27, 2006risk 0.00cvss —epss 0.02
Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.
- CVE-2000-0354Sep 28, 2000risk 0.00cvss —epss 0.02
mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.
Page 2 of 2