← Back

Busybox

busybox

Vendor: Busybox • 45 CVEs

CVEs (45)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Busybox
CanonicalDebian
3Busybox
Debian LinuxUbuntu Linux
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
1Busybox
1Busybox
May 6, 2026
Dec 9, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
3Busybox
RedhatT Mobile
3Busybox
Enterprise LinuxTm Ac1900
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
2Busybox
T Mobile
2Busybox
Tm Ac1900
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host nam...Show more
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.Show less
2Avaya
Busybox
5Aura Application Enablement Services
Aura Sip Enablement ServicesBusybox+2 more
Apr 16, 2026
Apr 4, 2006
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.