Known Vulnerabilities for products from BusyBox
Listed below are 20 of the newest known vulnerabilities associated with the vendor "BusyBox".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-93208 json | Not Provided | 2026-09-24 | 2026-09-24 | |
| CVE-2026-88840 json | Not Provided | 2026-09-23 | 2026-09-26 | |
| CVE-2026-88839 json | Not Provided | 2026-09-23 | 2026-09-25 | |
| CVE-2026-88837 json | Not Provided | 2026-09-23 | 2026-09-25 | |
| CVE-2026-88835 json | Not Provided | 2026-09-23 | 2026-09-25 | |
| CVE-2026-88832 json | Not Provided | 2026-09-23 | 2026-09-25 | |
| CVE-2026-88831 json | Not Provided | 2026-09-23 | 2026-09-25 | |
| CVE-2026-88830 json | Not Provided | 2026-09-23 | 2026-09-23 | |
| CVE-2026-76014 json | Not Provided | 2026-08-19 | 2026-08-25 | |
| CVE-2026-73055 json | Not Provided | 2026-08-15 | 2026-08-31 | |
| CVE-2026-38755 json | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service ... | Not Provided | 2026-07-15 | 2026-07-20 |
| CVE-2026-38754 json | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (... | Not Provided | 2026-07-15 | 2026-07-22 |
| CVE-2026-38753 json | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (... | Not Provided | 2026-07-15 | 2026-07-20 |
| CVE-2026-38752 json | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Se... | Not Provided | 2026-07-15 | 2026-07-20 |
| CVE-2025-60876 json | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), ... | Not Provided | 2025-11-10 | 2026-06-02 |
| CVE-2025-46394 json | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape s... | Not Provided | 2025-04-23 | 2026-06-02 |
| CVE-2023-42366 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-11-27 | 2023-11-30 |
| CVE-2023-42365 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-11-27 | 2023-11-30 |
| CVE-2023-42364 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-11-27 | 2023-11-30 |
| CVE-2023-42363 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-11-27 | 2023-11-30 |
Known software with vulnerabilities from BusyBox
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Busybox | Busybox | - |