Busybox

Busybox

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 02:45:08
  • Zuletzt bearbeitet 20.08.2026 12:48:31

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local...

  • EPSS 0.21%
  • Veröffentlicht 15.07.2026 00:00:00
  • Zuletzt bearbeitet 20.07.2026 16:16:59

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • EPSS 0.24%
  • Veröffentlicht 15.07.2026 00:00:00
  • Zuletzt bearbeitet 22.07.2026 15:16:54

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • EPSS 0.21%
  • Veröffentlicht 15.07.2026 00:00:00
  • Zuletzt bearbeitet 20.07.2026 16:16:58

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • EPSS 0.15%
  • Veröffentlicht 15.07.2026 00:00:00
  • Zuletzt bearbeitet 20.07.2026 16:16:58

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • EPSS 0.68%
  • Veröffentlicht 11.02.2026 20:27:06
  • Zuletzt bearbeitet 15.07.2026 02:19:00

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This c...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 10.11.2025 00:00:00
  • Zuletzt bearbeitet 02.06.2026 14:16:36

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line s...

  • EPSS 0.17%
  • Veröffentlicht 23.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.

  • EPSS 0.17%
  • Veröffentlicht 23.04.2025 00:00:00
  • Zuletzt bearbeitet 02.06.2026 14:16:33

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 27.11.2023 23:15:07
  • Zuletzt bearbeitet 03.11.2025 21:16:01

A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.