Debian Busybox vulnerabilities
44 known vulnerabilities affecting debian/busybox.
Total CVEs
44
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM8LOW16
Vulnerabilities
Page 3 of 3
CVE-2021-42373P4LOWCVSS 5.5fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42373 [MEDIUM] CVE-2021-42373: busybox - A NULL pointer dereference in Busybox's man applet leads to denial of service wh...
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
debian
CVE-2006-1058P4LOWCVSS 5.5fixed in busybox 1:1.1.3-1 (bookworm)2006
CVE-2006-1058 [MEDIUM] CVE-2006-1058: busybox - BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easi...
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
Scope: local
bookworm: resolved (fixed in 1:1.1.3-1)
bullseye: resolved (fixed in 1:1.1.3-1)
forky: resolved (fixed in 1:1.1.3-1)
sid: resolved (fixed in 1:1.1.3-1)
trixie: resolved
debian
CVE-2025-46394P4LOWCVSS 3.2fixed in busybox 1:1.37.0-8 (forky)2025
CVE-2025-46394 [LOW] CVE-2025-46394: busybox - In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a...
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.37.0-8)
sid: resolved (fixed in 1:1.37.0-8)
trixie: open
debian
CVE-2024-58251P4LOWCVSS 2.5fixed in busybox 1:1.37.0-9 (forky)2024
CVE-2024-58251 [LOW] CVE-2024-58251: busybox - In netstat in BusyBox through 1.37.0, local users can launch of network applicat...
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.37.0-9)
sid: resolved (fixed in 1:1.37.0-9)
trixie: open
debian
← Previous3 / 3