Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown

CVE-2017-15874

Disclosure Date: October 24, 2017 (last updated November 26, 2024)
archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
0
Attacker Value
Unknown

CVE-2011-5325

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
Attacker Value
Unknown

CVE-2014-9645

Disclosure Date: March 12, 2017 (last updated November 26, 2024)
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.
0
Attacker Value
Unknown

CVE-2016-2147

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
Attacker Value
Unknown

CVE-2016-2148

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
Attacker Value
Unknown

CVE-2016-6301

Disclosure Date: December 09, 2016 (last updated November 25, 2024)
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
0
Attacker Value
Unknown

CVE-2013-1813

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2011-2716

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
0
Attacker Value
Unknown

CVE-2006-5050

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.
0
Attacker Value
Unknown

CVE-2006-1058

Disclosure Date: April 04, 2006 (last updated February 22, 2025)
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.