Search CVE reports
1 – 10 of 59 results
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null...
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
1 affected package
busybox
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| busybox | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |