Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Busybox HIGH 7.5
CVE-2026-38752

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplyin…

Mitigation only
Fix from $1,950 2026-07-15
Busybox HIGH 7.5
CVE-2026-38755

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cr…

Mitigation only
Fix from $1,950 2026-07-15
Busybox MEDIUM 5.1
CVE-2026-38754

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra…

Mitigation only
Fix from $1,600 2026-07-15
Busybox HIGH 7.5
CVE-2026-38753

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra…

Mitigation only
Fix from $1,950 2026-07-15
Busybox MEDIUM 6.5
CVE-2025-60876

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request lin…

Fix: after 1.37.0
Fix from $1,600 2025-11-10
Busybox MEDIUM 5.5
CVE-2023-42364

A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate func…

No fix yet
Fix from $1,600 2023-11-27
Busybox MEDIUM 5.5
CVE-2023-42365

A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.

No fix yet
Fix from $1,600 2023-11-27
Busybox MEDIUM 5.5
CVE-2023-42366

A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.

No fix yet
Fix from $1,600 2023-11-27
Busybox MEDIUM 5.5
CVE-2023-42363

A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

No fix yet
Fix from $1,600 2023-11-27
Busybox HIGH 7.8
CVE-2023-39810

An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

Mitigation only
Fix from $1,950 2023-08-28
Busybox HIGH 7.8
CVE-2022-30065

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the c…

Fix: 3.0+
Fix from $1,950 2022-05-18
Busybox HIGH 8.8
CVE-2022-28391

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible term…

Fix: after 1.35.0
Fix from $1,950 2022-04-03
Busybox HIGH 8.1
CVE-2018-1000500

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This at…

Fix: 1.32.0+
Fix from $1,950 2018-06-26
Busybox MEDIUM 5.0
CVE-2017-15874

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

Patch available
Fix from $1,600 2017-10-24
Busybox MEDIUM 5.5
CVE-2014-9645

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules v…

Fix: after 1.22.1
Fix from $1,600 2017-03-12
Busybox HIGH 7.5
CVE-2016-6301EPSS 9%

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth cons…

Fix: 1.25.1+
Fix from $1,950 2016-12-09
Busybox MEDIUM 5.5
CVE-2006-1058

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file usi…

Fix: 4.0 / 5.0+
Fix from $1,600 2006-04-04