VYPR

Vendor CVEs

Busybox

All CVEs

61 total · sorted by risk
  • CVE-2025-2581MedMar 21, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. The manipulation leads to integer underflow. The attack can be launched remotely. Upgrading to version…

  • CVE-2026-88841lowSep 23, 2026
    risk 0.21cvss 3.3epss —

    busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption

  • CVE-2026-38755LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38752LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • CVE-2024-58251LowApr 23, 2025
    risk 0.16cvss 2.5epss 0.00

    In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.

  • CVE-2026-76014LowAug 19, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to…

  • CVE-2025-46394LowApr 23, 2025
    risk 0.14cvss 3.2epss 0.00

    In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

  • CVE-2013-1813Nov 23, 2013
    risk 0.00cvss —epss 0.01

    util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.

  • CVE-2011-2716Jul 3, 2012
    risk 0.00cvss —epss 0.02

    The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.

  • CVE-2006-5050Sep 27, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.

  • CVE-2000-0354Sep 28, 2000
    risk 0.00cvss —epss 0.02

    mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.

Page 2 of 2