📦 Busybox

by Busybox

🔍 What is Busybox?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-48174

CRITICAL CVSS 9.8 Aug 22, 2023

A stack overflow vulnerability in BusyBox's ash shell allows remote attackers to execute arbitrary code via crafted commands. This affects all systems running BusyBox versions before 1.35, particularl...

CVE-2021-42377

CRITICAL CVSS 9.8 Nov 15, 2021

CVE-2021-42377 is a critical vulnerability in BusyBox's hush shell applet where an attacker-controlled pointer free leads to denial of service and potential remote code execution when processing a cra...

CVE-2023-39810

HIGH CVSS 7.8 Aug 28, 2023

A directory traversal vulnerability in BusyBox's cpio command allows attackers to write files outside the intended extraction directory. This affects systems using BusyBox v1.33.2 with cpio functional...

CVE-2022-30065

HIGH CVSS 7.8 May 18, 2022

CVE-2022-30065 is a use-after-free vulnerability in BusyBox's awk applet that can be triggered by processing a specially crafted awk pattern. This vulnerability allows attackers to cause denial of ser...

CVE-2021-42383

HIGH CVSS 7.2 Nov 15, 2021

CVE-2021-42383 is a use-after-free vulnerability in BusyBox's awk applet that can be triggered by processing a specially crafted awk pattern. This vulnerability allows denial of service and potentiall...

CVE-2021-42385

HIGH CVSS 7.2 Nov 15, 2021

CVE-2021-42385 is a use-after-free vulnerability in BusyBox's awk applet that can be triggered by processing a specially crafted awk pattern. This vulnerability allows denial of service and potentiall...

CVE-2021-42379

HIGH CVSS 7.2 Nov 15, 2021

CVE-2021-42379 is a use-after-free vulnerability in BusyBox's awk applet that can be triggered by processing a specially crafted awk pattern. This could lead to denial of service or potentially remote...

CVE-2021-42381

HIGH CVSS 7.2 Nov 15, 2021

A use-after-free vulnerability in BusyBox's awk applet allows attackers to cause denial of service or potentially execute arbitrary code by providing a specially crafted awk pattern. This affects syst...

CVE-2025-60876

MEDIUM CVSS 6.5 Nov 10, 2025

BusyBox wget versions through 1.3.7 improperly accept raw CR/LF and C0 control characters in HTTP request targets, allowing attackers to split request lines and inject malicious headers. This vulnerab...