cbcvebase.

Debian Busybox vulnerabilities

44 known vulnerabilities affecting debian/busybox.

Total CVEs
44
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM8LOW16

Vulnerabilities

Page 3 of 3
CVE-2021-42373P4LOWCVSS 5.5fixed in busybox 1:1.35.0-1 (bookworm)2021
CVE-2021-42373 [MEDIUM] CVE-2021-42373: busybox - A NULL pointer dereference in Busybox's man applet leads to denial of service wh... A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given Scope: local bookworm: resolved (fixed in 1:1.35.0-1) bullseye: open forky: resolved (fixed in 1:1.35.0-1) sid: resolved (fixed in 1:1.35.0-1) trixie: resolved (fixed in 1:1.35.0-1)
debian
CVE-2006-1058P4LOWCVSS 5.5fixed in busybox 1:1.1.3-1 (bookworm)2006
CVE-2006-1058 [MEDIUM] CVE-2006-1058: busybox - BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easi... BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. Scope: local bookworm: resolved (fixed in 1:1.1.3-1) bullseye: resolved (fixed in 1:1.1.3-1) forky: resolved (fixed in 1:1.1.3-1) sid: resolved (fixed in 1:1.1.3-1) trixie: resolved
debian
CVE-2025-46394P4LOWCVSS 3.2fixed in busybox 1:1.37.0-8 (forky)2025
CVE-2025-46394 [LOW] CVE-2025-46394: busybox - In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a... In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:1.37.0-8) sid: resolved (fixed in 1:1.37.0-8) trixie: open
debian
CVE-2024-58251P4LOWCVSS 2.5fixed in busybox 1:1.37.0-9 (forky)2024
CVE-2024-58251 [LOW] CVE-2024-58251: busybox - In netstat in BusyBox through 1.37.0, local users can launch of network applicat... In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:1.37.0-9) sid: resolved (fixed in 1:1.37.0-9) trixie: open
debian