Debian Busybox vulnerabilities
44 known vulnerabilities affecting debian/busybox.
Total CVEs
44
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM8LOW16
Vulnerabilities
Page 1 of 3
CVE-2018-1000517P2LOWCVSS 9.8fixed in busybox 1:1.27.2-3 (bookworm)2018
CVE-2018-1000517 [CRITICAL] CVE-2018-1000517: busybox - BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1...
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in after commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e.
S
debian
CVE-2016-2148P2CRITICALCVSS 9.8fixed in busybox 1:1.27.2-1 (bookworm)2016
CVE-2016-2148 [CRITICAL] CVE-2016-2148: busybox - Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 ...
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed
debian
CVE-2026-26157P3HIGHCVSS 7.0PoCfixed in busybox 1:1.37.0-10.1 (forky)2026
CVE-2026-26157 [HIGH] CVE-2026-26157: busybox - A flaw was found in BusyBox. Incomplete path sanitization in its archive extract...
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system
debian
CVE-2022-48174P2CRITICALCVSS 9.8fixed in busybox 1:1.30.1-6+deb11u1 (bullseye)2022
CVE-2022-48174 [CRITICAL] CVE-2022-48174: busybox - There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In...
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.37.0-1)
sid: resolved (fixed in 1:1.37.0-1)
trixie: resolv
debian
CVE-2021-42377P3LOWCVSS 9.8fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42377 [CRITICAL] CVE-2021-42377: busybox - An attacker-controlled pointer free in Busybox's hush applet leads to denial of ...
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
f
debian
CVE-2017-16544P3HIGHCVSS 8.8fixed in busybox 1:1.27.2-2 (bookworm)2017
CVE-2017-16544 [HIGH] CVE-2017-16544: busybox - In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab...
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
Scope: local
bookworm: r
debian
CVE-2014-4607P3HIGHCVSS 8.8fixed in busybox 1:1.22.0-10 (bookworm)2014
CVE-2014-4607 [HIGH] CVE-2014-4607: busybox - Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 bef...
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
Scope: local
bookworm: resolved (fixed in 1:1.22.0-10)
bullseye: resolved (fixed in 1:1.22.0-10)
forky: resolved (fixed in 1:1.22.0-10)
sid: resolved (fixed in 1:1.22.0-10)
trixie
debian
CVE-2018-20679P3LOWCVSS 7.5fixed in busybox 1:1.30.1-1 (bookworm)2018
CVE-2018-20679 [HIGH] CVE-2018-20679: busybox - An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp...
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.
debian
CVE-2011-5325P3HIGHCVSS 7.5fixed in busybox 1:1.27.2-1 (bookworm)2011
CVE-2011-5325 [HIGH] CVE-2011-5325: busybox - Directory traversal vulnerability in the BusyBox implementation of tar before 1....
Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (
debian
CVE-2019-5747P3HIGHCVSS 7.5fixed in busybox 1:1.30.1-2 (bookworm)2019
CVE-2019-5747 [HIGH] CVE-2019-5747: busybox - An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhc...
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to assurance of a 4-byte length when decoding DHCP_SUBNET. NOTE: this issue exists because of an in
debian
CVE-2021-42380P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42380 [HIGH] CVE-2021-42380: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.
debian
CVE-2021-42385P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42385 [HIGH] CVE-2021-42385: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.3
debian
CVE-2021-42379P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42379 [HIGH] CVE-2021-42379: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed i
debian
CVE-2021-42381P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42381 [HIGH] CVE-2021-42381: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.
debian
CVE-2021-42382P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42382 [HIGH] CVE-2021-42382: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.3
debian
CVE-2021-42384P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42384 [HIGH] CVE-2021-42384: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in
debian
CVE-2021-42378P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42378 [HIGH] CVE-2021-42378: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.3
debian
CVE-2021-42386P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42386 [HIGH] CVE-2021-42386: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35
debian
CVE-2021-42383P3HIGHCVSS 7.2fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42383 [HIGH] CVE-2021-42383: busybox - A use-after-free in Busybox's awk applet leads to denial of service and possibly...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
debian
CVE-2011-2716P3LOWCVSS 6.8fixed in busybox 1:1.20.0-3 (bookworm)2011
CVE-2011-2716 [MEDIUM] CVE-2011-2716: busybox - The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to ...
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
Scope: local
bookworm: resolved (fixed in 1:1.20.0-3)
bullseye: resolved (fixed in 1:1.20.0-3)
forky: resolved (fixed in 1:1.20.0-3)
sid:
debian
1 / 3Next →