Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown
CVE-2017-15874
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
0
Attacker Value
Unknown
CVE-2011-5325
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
0
Attacker Value
Unknown
CVE-2014-9645
Disclosure Date: March 12, 2017 (last updated November 26, 2024)
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.
0
Attacker Value
Unknown
CVE-2016-2147
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
0
Attacker Value
Unknown
CVE-2016-2148
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
0
Attacker Value
Unknown
CVE-2016-6301
Disclosure Date: December 09, 2016 (last updated November 25, 2024)
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
0
Attacker Value
Unknown
CVE-2013-1813
Disclosure Date: November 23, 2013 (last updated October 05, 2023)
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2011-2716
Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
0
Attacker Value
Unknown
CVE-2006-5050
Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.
0
Attacker Value
Unknown
CVE-2006-1058
Disclosure Date: April 04, 2006 (last updated February 22, 2025)
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
0