Vulnerabilities
Vulnerable Software
Busybox:  >> Busybox  >> 0.60.4  Security Vulnerabilities
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
CVSS Score
7.5
EPSS Score
0.03
Published
2017-02-09
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVSS Score
9.8
EPSS Score
0.143
Published
2017-02-09
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
CVSS Score
7.5
EPSS Score
0.045
Published
2016-12-09
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
CVSS Score
7.2
EPSS Score
0.0
Published
2013-11-23
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
CVSS Score
6.8
EPSS Score
0.012
Published
2012-07-03


Contact Us

Shodan ® - All rights reserved