Search CVE reports


Toggle filters

31 – 40 of 44 results


CVE-2018-1000517

Medium priority

Some fixes available 9 of 10

BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable...

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Fixed Fixed
Show less packages

CVE-2017-16544

Medium priority

Some fixes available 9 of 11

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape...

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Fixed Fixed
Show less packages

CVE-2017-15874

Negligible priority
Not affected

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox
Show less packages

CVE-2017-15873

Low priority

Some fixes available 9 of 11

The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Fixed Fixed
Show less packages

CVE-2011-5325

Low priority

Some fixes available 9 of 15

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Fixed Fixed
Show less packages

CVE-2014-9645

Low priority

Some fixes available 1 of 5

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig...

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Not affected Not affected
Show less packages

CVE-2016-2148

Low priority

Some fixes available 2 of 6

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Not affected
Show less packages

CVE-2016-2147

Low priority

Some fixes available 2 of 7

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Not affected Not affected
Show less packages

CVE-2016-6301

Low priority
Not affected

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox
Show less packages

CVE-2013-1813

Negligible priority
Ignored

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.

1 affected package

busybox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
busybox Not affected Not affected
Show less packages