Busybox

Busybox

41 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.31%
  • Published 20.11.2017 15:29:00
  • Last modified 09.06.2025 16:15:26

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the termin...

Exploit
  • EPSS 0.19%
  • Published 24.10.2017 20:29:00
  • Last modified 09.06.2025 16:15:26

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

Exploit
  • EPSS 0.12%
  • Published 24.10.2017 20:29:00
  • Last modified 09.06.2025 16:15:26

The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

Exploit
  • EPSS 5.8%
  • Published 07.08.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

  • EPSS 0.31%
  • Published 12.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or ...

Exploit
  • EPSS 15.03%
  • Published 09.02.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.

Exploit
  • EPSS 2.2%
  • Published 09.02.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

  • EPSS 4.75%
  • Published 09.12.2016 20:59:01
  • Last modified 12.04.2025 10:46:40

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

Exploit
  • EPSS 0.03%
  • Published 23.11.2013 11:55:04
  • Last modified 11.04.2025 00:51:21

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.

  • EPSS 0.71%
  • Published 03.07.2012 16:40:30
  • Last modified 11.04.2025 00:51:21

The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.