CVE-2011-5325
- EPSS 7.18%
- Veröffentlicht 07.08.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
CVE-2014-9645
- EPSS 0.64%
- Veröffentlicht 12.03.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or ...
CVE-2016-2148
- EPSS 27.11%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-2147
- EPSS 7.65%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
CVE-2016-6301
- EPSS 8.89%
- Veröffentlicht 09.12.2016 20:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
CVE-2013-1813
- EPSS 0.62%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
CVE-2011-2716
- EPSS 1.8%
- Veröffentlicht 03.07.2012 16:40:30
- Zuletzt bearbeitet 16.06.2026 23:31:51
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
CVE-2006-1058
- EPSS 0.29%
- Veröffentlicht 04.04.2006 10:04:00
- Zuletzt bearbeitet 16.06.2026 22:21:56
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.