← Back

Busybox

busybox

45 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Busybox
busybox

CVEs (45)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Busybox
1Busybox
Jul 20, 2026
Jul 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
1Busybox
1Busybox
Jul 22, 2026
Jul 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
1Busybox
1Busybox
Jul 20, 2026
Jul 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
1Busybox
1Busybox
Jul 20, 2026
Jul 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
1Busybox
1Busybox
Jun 17, 2026
Nov 10, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preser...Show more
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).Show less
1Busybox
1Busybox
Jun 17, 2026
Apr 23, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
1Busybox
1Busybox
Jun 17, 2026
Nov 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
1Busybox
1Busybox
Jun 17, 2026
Nov 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.
1Busybox
1Busybox
Jun 17, 2026
Nov 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
1Busybox
1Busybox
Jun 17, 2026
Nov 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
1Busybox
1Busybox
Jul 9, 2026
Aug 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
2Busybox
Debian
2Busybox
Debian Linux
Jul 14, 2026
Aug 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
2Busybox
Siemens
7Busybox
Scalance Sc622 2c FirmwareScalance Sc626 2c Firmware+4 more
Jul 7, 2026
May 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
1Busybox
1Busybox
Jun 17, 2026
Apr 3, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's...Show more
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.Show less
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function